Rootful Podman restarts a --uidmap container once on an AppArmor host, then gives up
TL;DR : On a host with AppArmor enabled, a rootful Podman container that has its own ID mapping ( --uidmap / --gidmap ) and a restart policy is restarted once at most. When it exits the second time it stays exited . podman events shows died , restart , and then nothing, and RestartCount stops at 1. The process that should restart it, podman container cleanup , fails with profile…
Podman, when run with root privileges, will only restart a container with its own user and group ID mappings (uidmap / gidmap) once on a host that has AppArmor enabled. Once restarted, the container will remain in an exited state even if it exits again. This behavior can be observed in the container's event log, which will show a "died" message followed by a "restart" message, and then nothing further, with the restart count stopping at 1.
The process responsible for restarting the container, podman container cleanup, fails with a profile specified, but AppArmor is disabled on the host. The error is only logged if the container was created with podman --syslog. The issue has been reported upstream as podman-container-tools/podman#29925.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.