Troubleshoot a failed apply¶
An apply fails in one of two places: while syslet builds the plan, before anything on the host changes, or while it carries the plan out. The output tells you which.
The plan has errors¶
A plan with any error is refused as a whole, and nothing on the host changes.
--diff and an apply both print the errors to stderr, instead of the diff or the results:
| Text Only | |
|---|---|
The prefix names the stage that failed (see Safety mechanisms):
pre-render validationandpost-render validation: syslet's own checks on the specs, such as references to missing specs or secret keys, overlapping mount paths, orconfigDirswithoutExecReload=. The message names the spec; fix it and preview again.error [<unit>]: a check on one unit against the host, such as a volume change that the installed markers don't allow (see Manage volumes), orchecking image, when podman can't tell whether the container's image is on the host.secret "<name>": decryption failed: the host can't decrypt the file. Check that it's encrypted to the host's key (see Add a SOPS recipient).quadlet generator failedandunit verification failed: podman's generator orsystemd-analyze verifyrejected the rendered units, usually because of a misspelled option or a value podman doesn't accept.unit verification warnings:systemd-analyze verifyaccepted the units but would ignore a setting, such asInvalid memory limit 'asd', ignoring: Invalid argument. syslet refuses these like failures, since the unit wouldn't run as specified; fix the setting it names.
Inspect the staged units¶
For generator and verification errors, syslet writes the rendered units into a staging directory and keeps it. Its path is in syslet's log on stderr:
| Text Only | |
|---|---|
units/ holds the quadlet files syslet would install, and out/ what podman's generator made of them.
Run the generator by hand to see its full output:
| Bash | |
|---|---|
Messages the generator logged during the plan are in the journal:
| Bash | |
|---|---|
A unit failed during the apply¶
When the plan was fine but an operation failed, syslet logs the failure, carries on with the rest of the plan and exits with an error:
| Text Only | |
|---|---|
Most failures are a container that doesn't start, for example because the process exits. Look at the service:
job result dependency means a unit the container requires failed first, such as its volume, network or build; check that unit's service the same way.
The files syslet wrote before the failure stay in place. Fix the cause and apply again: syslet diffs against what's now installed and starts the container again, since it isn't running.
An image can't be pulled¶
syslet pulls missing images before any other change. If a pull fails, the apply stops there, so nothing on the host changes and the old containers keep running:
Every container that needs the image gets an error row. Check the image name and tag, and that the host can reach the registry:
| Bash | |
|---|---|
Then apply again.