Manage networks¶
This guide covers adding, changing, locking and removing a network spec.
A network holds no data, so syslet recreates a changed network on its own; only removal is guarded by removalAllowed.
Know your defaults¶
The setup only decides what happens when you drop a network's spec:
| Setup | Spec dropped | Spec changed |
|---|---|---|
| Default, CUE or JSON | Unit and podman network removed | Recreated |
| Locked | Unit and network kept | Recreated |
When the unit is removed, reclaimPolicy decides whether the podman network goes with it: "Delete" (the default) removes it, "Retain" leaves it behind.
Add a network¶
Attach a container to it in the same input:
syslet names the podman network after the spec, here webapp-net.
The network's service, webapp-net-network.service, creates it when the first container on it starts; a network no container references is never created.
See Connect containers on a network for name resolution between containers.
Change a network¶
Podman can't reconfigure a network in place.
Changing [Unit] Description, removalAllowed or reclaimPolicy only rewrites the unit file; any other change recreates the network.
Unlike a volume, a network needs no markers for that, not even when it's locked. Preview the change:
The plan stops every running container attached to the network, deletes the podman network and starts the containers again, which creates the new network:
| Text Only | |
|---|---|
If something outside syslet still uses the podman network, the delete fails, and the apply fails with the network marked error.
Disconnect the containers that podman ps -a --filter network=webapp-net lists, then apply again.
Lock a network¶
Lock the network and apply:
A locked network is skipped when its spec disappears from the input, but changes still recreate it.
Remove a network¶
- Drop the network from every container's
Network=. A network that is still referenced fails validation. - Make sure the installed unit allows removal. If it's locked, drop it from
#SysdefLock(in JSON, set"removalAllowed": trueor omit it), keep the spec, and apply once. - Drop the network spec, preview and apply.
Steps 1 and 3 can go into the same change.
The plan shows the network as removed, and under reclaimPolicy: "Delete" also lists it in Podman networks to delete:.
Under Retain, the podman network stays behind; delete it by hand:
| Bash | |
|---|---|