Quadlet does not support User= in system units: the generated pod service writes its conmon pidfile to %t/%N.pid, which resolves to /run/authelia-pod.pid and is unwritable by the authelia user, so authelia-pod.service always failed with status 125. See podman-systemd.unit(5). - Move all quadlet files and drop-ins to the rootless search path /etc/containers/systemd/users/126; units now run in the authelia user's systemd manager, started at boot via linger - Drop the [Service] User=/HOME overrides from the quadlet files - Enable the pod via WantedBy=default.target - Make /etc/authelia authelia-owned so rootless podman can relabel the config bind mount (:z) - Replace system-unit systemd macros in the -container scriptlets with systemctl --user -M authelia@ daemon-reload / stop
7 lines
92 B
INI
7 lines
92 B
INI
[Unit]
|
|
Description=Authelia pod
|
|
|
|
[Pod]
|
|
PodName=authelia-pod
|
|
PublishPort=127.0.0.1:9091:9091
|