You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
fakecloud decides whether its container CLI is podman purely from the binary's file name: container_net::is_podman_binary checks whether the name contains podman. On distros that ship the podman-docker package (Fedora, RHEL, CentOS Stream, and others), docker is a shim that execs podman. When docker is found first (or FAKECLOUD_CONTAINER_CLI=docker is set), fakecloud treats podman as Docker and takes every Docker-only code path.
crates/fakecloud-core/src/container_net.rs: resolve_host_alias uses host.containers.internal with no --add-host for podman. Behind the shim, it passes --add-host host.docker.internal:host-gateway (or the bridge IP on Linux), which is the combination podman rejected in Lambdas on macOS #1539.
crates/fakecloud-ec2/src/runtime/mod.rs: network_isolation_summary reports backend: "docker" from /_fakecloud/ec2/instance-networks even though podman is running.
Expected
Detect the runtime by what it is, not by what it's called. docker --version behind the shim prints podman version X.Y.Z, and <cli> info exposes podman-specific fields. Probe once per CLI (bounded, like the existing cli_available probe), cache the result, and have every current is_podman_binary caller use it. Keep the name match as a fast path.
Repro
On Fedora or RHEL, install podman-docker without Docker.
Run fakecloud with the default CLI detection, which picks docker.
Push an image to fakecloud ECR and run an ECS task that references <account>.dkr.ecr.<region>.amazonaws.com/<repo>:<tag>.
The task stops with TaskFailedToStart, and the image pull fails with an HTTPS error.
Problem
fakecloud decides whether its container CLI is podman purely from the binary's file name:
container_net::is_podman_binarychecks whether the name containspodman. On distros that ship thepodman-dockerpackage (Fedora, RHEL, CentOS Stream, and others),dockeris a shim that execs podman. Whendockeris found first (orFAKECLOUD_CONTAINER_CLI=dockeris set), fakecloud treats podman as Docker and takes every Docker-only code path.Places that branch on this today:
crates/fakecloud-core/src/container_image.rs:pull_argsadds--tls-verify=falseonly for podman when pulling from fakecloud's own plain-HTTP ECR registry (fix(ecs,lambda): pull fakecloud's ECR registry over plain HTTP under podman #2595). Behind the shim, the flag is skipped, and ECS tasks and image-based Lambda functions fail exactly as in Podman-backed ECS tries to connect to 127.0.0.1 over HTTPS instead of HTTP #2585:server gave HTTP response to HTTPS client.crates/fakecloud-core/src/container_net.rs:resolve_host_aliasuseshost.containers.internalwith no--add-hostfor podman. Behind the shim, it passes--add-host host.docker.internal:host-gateway(or the bridge IP on Linux), which is the combination podman rejected in Lambdas on macOS #1539.crates/fakecloud-ec2/src/runtime/mod.rs:network_isolation_summaryreportsbackend: "docker"from/_fakecloud/ec2/instance-networkseven though podman is running.Expected
Detect the runtime by what it is, not by what it's called.
docker --versionbehind the shim printspodman version X.Y.Z, and<cli> infoexposes podman-specific fields. Probe once per CLI (bounded, like the existingcli_availableprobe), cache the result, and have every currentis_podman_binarycaller use it. Keep the name match as a fast path.Repro
podman-dockerwithout Docker.docker.<account>.dkr.ecr.<region>.amazonaws.com/<repo>:<tag>.TaskFailedToStart, and the image pull fails with an HTTPS error.Follow-up to #2585 / #2595.