Added
- runtime/engine — checkpoint/restore via an optional
CheckpointRuntimesub-interface plus a new Podman backend that
implements it. Docker's checkpoint/restore is broken on current
engines (the netns bind-mount on restore — upstream containerd#12141 /
moby#37344), so Podman does the full round trip (checkpoint --export
/restore --import: process + memory + writable rootfs in a portable,
node-independent archive). Addsruntime.CheckpointRuntime,
CheckpointSpec/RestoreSpec/CheckpointRef,Capabilities.Checkpoint,
typed errors (ErrCheckpointUnsupported,CheckpointFailedError,
RestoreFailedError),Engine.Checkpoint/Engine.Restore(Restore
returns a fully reattached*Workspace), and
Engine.CheckpointProject/RestoreProjectfor multi-service compose
projects (enumerated by thecom.docker.compose.projectlabel). (#98)
Fixed
- compose — Dev Container Feature security metadata (
privileged,
init,capAdd,securityOpt) andentrypointscripts are now
applied to docker-compose services, matching the reference
devcontainers/cli. Previously the metadata was merged into
ResolvedConfigbut never carried onto the service, so features like
docker-in-docker silently failed on compose-source devcontainers:
the daemon came up unprivileged and itsdocker-init.shentrypoint
never ran. Feature entrypoints are now chained ahead of the service
command via a generated wrapper (native and shellout paths), and
ContainerDetailssurfacesPrivileged/CapAdd/SecurityOptfrom
inspect. A failed image inspect in the entrypoint-preservation fallback
now emits aWarnEventinstead of silently dropping the image
ENTRYPOINT. Image-source (non-compose) entrypoint chaining and
overrideCommandgating remain follow-ups (#104). (#103) - compose/podman — orchestrator-driven health probing on Podman.
Podman runs a container'sHEALTHCHECKas root and fires the first
probe immediately at start (ignoringstart_period), which breaks
privilege-dropping images — e.g. RabbitMQ'srabbitmq-diagnostics
probe creates a root-owned.erlang.cookiethe gosu-dropped uid-999
server can't read. The compose orchestrator now probes health itself on
backends that opt in (Podman returns true; Docker and Apple unchanged),
deferring the first probe until after the service initializes, matching
Docker. Also fixes multi-service checkpoint/restore. See
design/compose-native-health.md. (#102)
Changed
- deps — bump
github.com/google/go-containerregistry0.21.6 →
0.21.7. (#101) - dev environment / CI — prebuild-based dev environment + CI (#88);
pin prebuild base to bookworm (#89); use Compose v2 in
docker-in-docker (#90); skip legacydocker-composein
docker-in-docker (#91); pin docker-in-docker to 2.x (#92); add:sha
image tag and prune stale build intermediates (#93).
Full changelog: v0.3.0...v0.4.0