--- # The image runs as uid 10001 (scratch, no passwd file). Rootless podman maps # container uid N to host uid subuid_start + N - 1, so own the directory as # that host uid directly. Setting the podman user here and chowning back # afterwards would flip ownership on every deploy and briefly lock the running # app out of its own database directory. - name: create rsvp host directory volumes become: true ansible.builtin.file: path: "{{ item }}" state: directory owner: "{{ podman_subuid.stdout | int + 10000 }}" group: "{{ podman_subuid.stdout | int + 10000 }}" mode: 0750 notify: restorecon podman loop: - "{{ rsvp_path }}/data" - name: flush handlers ansible.builtin.meta: flush_handlers - import_tasks: podman/podman-check.yml vars: container_name: rsvp container_image: "{{ image }}" - name: create rsvp container become: true become_user: "{{ podman_user }}" containers.podman.podman_container: name: rsvp image: "{{ image }}" restart_policy: on-failure:3 log_driver: journald env: RSVP_DB_PATH: /data/rsvp.db RSVP_BASE_URL: "https://{{ rsvp_server_name }}" RSVP_TZ: America/New_York # Client IPs for the invite-link miss limiter come from Caddy's # X-Forwarded-For. Safe only because both ports are loopback-only. RSVP_TRUST_FORWARDED: "1" volumes: - "{{ rsvp_path }}/data:/data" ports: - "127.0.0.1:{{ rsvp_public_port }}:8080" - "127.0.0.1:{{ rsvp_admin_port }}:8081" - name: create systemd startup job for rsvp include_tasks: podman/systemd-generate.yml vars: container_name: rsvp