Moving the Graph Root to a New Path
Goal
Move the graph root of rootless podman from home to a separate path, and refill the new store with images. It is the podman operations task you perform most often in practice.
Why it matters
Images of rootless podman pile up in ~/.local/share/containers/storage. On a GPU server where one CUDA base image is 8GB, the home partition fills in no time. And when home fills up, not only podman but everything that user does stops. That is why the standard configuration of a GPU node often includes moving graphroot from the start.
Two things to watch for. The new store is empty — the existing images stay on the old path and podman no longer sees them. And you do not move runroot — it holds runtime locks and temporary state, so it must be tmpfs.
Steps
- Create the
/root/grdirectory, and writepodster's currentgraphRootandrunRoot, one per line (graphRoot first), in/root/gr/before.txt. - Create the new path
/srv/podman/podster, and set its owner topodsterand its permissions to700. - In
podster'sstorage.conf, changegraphrootto the new path. - Use
podman infoto confirm thatgraphRootis the new path, and write it on one line in/root/gr/after.txt. - Write the number of images in the new store, as one line with a number, in
/root/gr/empty.txt. It must be0. - Load
/opt/images/labhub-alpine.tarinto the new store, and save the image list after loading to/root/gr/images.txt. There must be at least 1. - Create
/root/gr/runroot.txtwith the following 2 lines.RUNROOT=<현재 runRoot 값>/WHY=tmpfs(the placeholder is the current runRoot value) - Create
/root/gr/report.txtwith the following 4 lines.OLD=<1번의 graphRoot>/NEW=/srv/podman/podster/IMAGES_BEFORE=0/IMAGES_AFTER=<6번 이후 이미지 개수>(the placeholders are the graphRoot from step 1 and the image count after step 6)
Notes
- You can extract a single value with
su - podster -c "podman info --format '{{.Store.GraphRoot}}'". - Count images with
podman images --format '{{.Repository}}' | wc -l. - Load with
podman load -i /opt/images/labhub-alpine.tar. - The container runtime may be blocked on this node. In that case the command ends with an error such as
cannot re-exec process, and you should save that output to the file as it is too. How rootless podman fails in an environment where creating unprivileged user namespaces is blocked is itself worth learning, and in this case grading is based on the configuration you wrote. - Common mistake 1: leaving the new path owned by root so that podman cannot write to it.
- Common mistake 2: editing
storage.confas root so that the owner changes. Check the ownership again after editing.
Record the current paths
Create the /root/gr directory, and write podster's current graphRoot and runRoot, one per line (graphRoot first), in /root/gr/before.txt.
podman info has an option that extracts specific values with a Go template. The paths are under Store.
Prepare the new path
Create the new path /srv/podman/podster, and set its owner to podster and its permissions to 700.
Owner and permissions matter. That user must be able to read and write, and others must not be able to look inside.
Edit storage.conf
In podster's storage.conf, change graphroot to the new path.
Change only the graphroot value in the [storage] section. Keep the quotation marks.
Confirm the new path took effect
Use podman info to confirm that graphRoot is the new path, and write it on one line in /root/gr/after.txt.
After fixing the configuration, running info again should show a changed value. If it does not change, suspect ownership or the path.
Confirm the new store is empty
Write the number of images in the new store, as one line with a number, in /root/gr/empty.txt. It must be 0.
Listing the images should show only the header and no entries. Count them and write the number to the file.
Load the image archive
Load /opt/images/labhub-alpine.tar into the new store, and save the image list after loading to /root/gr/images.txt. There must be at least 1.
podman has a command that reads images from a tar archive. It should appear in the list after loading.
Check runroot and record the reason
Create /root/gr/runroot.txt with the following 2 lines.
RUNROOT=<현재 runRoot 값> / WHY=tmpfs (the placeholder is the current runRoot value)
You do not move runroot. Write the reason why, using the fixed keyword.
Migration report
Create /root/gr/report.txt with the following 4 lines.
OLD=<1번의 graphRoot> / NEW=/srv/podman/podster / IMAGES_BEFORE=0 / IMAGES_AFTER=<6번 이후 이미지 개수> (the placeholders are the graphRoot from step 1 and the image count after step 6)
Gather the before and after paths and the image counts. The values must be ones you actually checked.