ansible / ansible/molecule

Podman driver silently ignores `memory`, `memory_swap`, and `pids_limit` platform fields

Open Beginner friendly
#4,690 0 comments 0 reactions 0 assignees View on GitHub
new
Dominant language
Python
Stars
4.1k
Forks
676
Avg merge
4d 14h
Merged PRs (30d)
9

Description

### Prerequisites

- [x] This was not already reported in the past (duplicate check)
- [x] It does reproduce it with code from main branch (latest unreleased version)
- [x] I include a minimal example for reproducing the bug
- [x] The bug is not trivial, as for those a direct pull-request is preferred
- [x] Running `pip check` does not report any conflicts
- [x] I was able to reproduce the issue on a different machine
- [x] The issue is not specific to any driver other than 'default' one

### Environment

molecule 26.6.0
molecule-plugins 25.8.12
containers.podman collection 1.16.2
podman version 4.6.2
Operating system: Ubuntu 22.04.5 LTS (Jammy Jellyfish)
Kernel: Linux 5.19.17-051917-generic
Architecture: x86_64
Python: 3.10.12
rootless: true
cgroup version: v2
cgroup filesystem: cgroup2fs
cgroup manager: systemd

### What happened

The bundled Molecule Podman create playbook silently ignores the platform fields
`memory`, `memory_swap`, and `pids_limit`. The same platform's `ulimits` field is
forwarded correctly.

### Reproducing example

```yml
## Summary

The bundled Molecule Podman create playbook silently ignores the platform fields
`memory`, `memory_swap`, and `pids_limit`. The same platform's `ulimits` field is
forwarded correctly.

The underlying `containers.podman.podman_container` module supports all four
parameters, and passing the missing limits through the Podman driver's
`extra_opts` produces the expected container configuration.

The bundled Docker create playbook already forwards `memory` and `memory_swap`,
making equivalent Molecule platform configuration inconsistent between Docker
and Podman.

## Minimal reproduction

---
driver:
name: podman

platforms:
- name: molecule-podman-limits-repro
image: docker.io/geerlingguy/docker-ubuntu2204-ansible:latest
pre_build_image: true
command: sleep infinity
memory: 268435456
memory_swap: 536870912
pids_limit: 1234
ulimits:
- nofile=4096:4096
- nproc=8192:8192

provisioner:
name: ansible

scenario:
create_sequence:
- create
destroy_sequence:
- destroy

Run:

molecule create -s default
podman inspect molecule-podman-limits-repro \
--format 'Memory={{.HostConfig.Memory}} MemorySwap={{.HostConfig.MemorySwap}} PidsLimit={{.HostConfig.PidsLimit}} Ulimits={{json .HostConfig.Ulimits}}'

## Actual result

Memory=0
MemorySwap=0
PidsLimit=16384
Ulimits=[
{"Name":"RLIMIT_NOFILE","Soft":4096,"Hard":4096},
{"Name":"RLIMIT_NPROC","Soft":8192,"Hard":8192}
]

`PidsLimit=16384` is the user's Podman `containers.conf` default. The requested
value `1234` was not applied. Memory and swap are unlimited (`0`). Both ulimits
were applied correctly.

## Source evidence

Installed bundled Podman playbook:

molecule_plugins/podman/playbooks/create.yml

The `containers.podman.podman_container` task maps:

ulimits: "{{ item.ulimits | default(omit) }}"

It has no mappings for:

memory: "{{ item.memory | default(omit) }}"
memory_swap: "{{ item.memory_swap | default(omit) }}"
pids_limit: "{{ item.pids_limit | default(omit) }}"

By comparison, the installed bundled Docker playbook maps at least:

memory: "{{ item.memory | default(omit) }}"
memory_swap: "{{ item.memory_swap | default(omit) }}"
ulimits: "{{ item.ulimits | default(omit) }}"

The underlying `containers.podman.podman_container` module supports `memory`,
`memory_swap`, `pids_limit`, and `ulimits`, so the values are lost in the Molecule
Podman adapter rather than Podman or the Ansible collection.

## Control test using `extra_opts`

Adding:

extra_opts:
- --memory=268435456
- --memory-swap=536870912
- --pids-limit=1234

and recreating the container produced:

Memory=268435456
MemorySwap=536870912
PidsLimit=1234
Ulimits=[
{"Name":"RLIMIT_NOFILE","Soft":4096,"Hard":4096},
{"Name":"RLIMIT_NPROC","Soft":8192,"Hard":8192}
]

This confirms Podman accepts the limits and isolates the omission to the bundled
Molecule Podman create playbook.

## Expected behavior

The Podman driver should either:

1. Forward these platform fields to `podman_container`, consistently with the
Docker driver and the underlying module; or
2. Validate/reject unsupported platform fields instead of silently ignoring them,
and document `extra_opts` as the required interface.

Preferred mapping:

memory: "{{ item.memory | default(omit) }}"
memory_swap: "{{ item.memory_swap | default(omit) }}"
pids_limit: "{{ item.pids_limit | default(omit) }}"

## Workaround

Use per-platform `extra_opts`:

extra_opts:
- --memory=4g
- --memory-swap=4g
- --pids-limit=16384

`ulimits` can continue using the native platform field:

ulimits:
- nofile=65536:65536
- nproc=16384:16384

Do not conflate `nproc` with `pids_limit`: `nproc` is an RLIMIT passed through
`ulimits`, while `pids_limit` controls the container's cgroup PID limit.
```

Contributor guide

Open the contributing guide

Research direction

Start with molecule_plugins/podman/playbooks/create.yml and inspect the containers.podman.podman_container task alongside the existing ulimits mapping. Add forwarding for the three platform fields described in the issue, then run the provided molecule create and podman inspect reproduction to confirm the requested memory, swap, and PID limits are applied.

Written by the indexing model from the issue text.

Assessment

Tech stack
ansible, python
Domain
devops, testing
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Active
Clarity
Clearly specified
Newbie friendliness
84/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.