EDIT: For some context, I recently gave podman another go. I have a few services on my homelab server set up in docker containers, so I tried migrating to podman.
After the second major bug (open issue on github) I encountered looked like it would require completely dropping using compose files to work around, I gave up and went back to docker.
I like the idea of podman, but it’s just not stable. I’ll try again in a year or so.
As a bonus, docker’s CLI is significantly nicer.
Podman is unironically the better choice. Just try to make docker comply with your firewall…
Docker bypasses your firewall and runs as root. Only an idiot would allow that shit… I’m an idiot. But I’m fixing that.
It doesn’t “bypass your firewall”… it lets you shoot yourself in the foot. You’re asking it to open ports without specifying an explicit network interface so it opens them on all interfaces. Which includes opening up the firewall, because what’s the point of putting up a service and blocking it in the firewall.
Also, doing it by hand would be incredibly tedious. Docker automatically adjusts the rules to match the ports and interfaces to its private container netmasks, and brings them up or down as needed when the containers start/stop.
All you have to do is bind ports to localhost or to a private interface if you don’t want the service to be publicly exposed.
Beginners get bitten by this because they say
ports: 9999:9999instead ofports: 127.0.0.1:9999:9999/tcplike they should. Unfortunately most examples out there use the terse version and never explain why it’s bad.
Podman is unironically the better choice.
I like the idea of podman, but it’s just not stable. This meme was inspired by my frustration of trying to switch.
Just try to make docker comply with your firewall.
I literally did this yesterday and it wasn’t that hard. You just add
iptables:Falseto the docker config file.This + forwarding stuff to the docker namespace is working great for me. https://wiki.archlinux.org/title/Nftables#Working_with_Docker
Cult
I choose Podman bc it’s open source and that’s kind of the reason for using everything as a container bc those are often also open source. Fuck docker
It also can integrate with Systemd via Quadlets. Let’s you control containers as a sytemd service. I personally use them for my home server and have been happy with it.
The learning curve for quadlets is quite harsh in my opinion. I started with podman compose 3 years ago for my homelab, because it allowed user containers.
I tried to migrate to quadlets unsuccessfully, several times over the years. it was only recently that my self-hosted Qwen was capable enough to figure out where I was messing up and automate the process a bit.
I probably wasn’t sufficiently motivated. It felt like podman compose is basically docker compose, but quadlets are a quite a bit different in form and function, so I was never able to grok them:
There is a tool named Podlet that can help translate to quadlets. I was able to fully translate my unraid and compose setups to quadlets.
I remember trying it and my compose files blew up to multiple Quadlet files with a much larger total size (lines of code). I find that compose is just more concise and structured compared to Quadlets.
It does have a larger file size compared to compose, sure. The big advantage of quadlets is that systemd will handle things in the event of a failure. It makes it a great option for production environments where you will not need to update your config files as much. It also allows you to have more control over when each application starts, if they rely on a specific disk mount or service running on the system. I’m sure someone else can provide more benefits who use them in a production environment.
Fair enough. My requirements are simply: start all services when the machine has finished booting. And I can’t remember the last time my system failed. Most that happened was a power outage, and Quadlets wouldn’t have helped there either.
So in my case I much prefer simple and easy-to-read configs, over the complexity of integrating with systemd.
Docker compose definitely works for most people, so I would feel pressured to swap.
There is one instance where Quadlets would have fixed an issue we ran into at work. We had a Kafka instance whose container died and went away because we ran out of space on the server. Compose doesn’t recreate containers on failure, so I was called in to fix the issue. Quadlets treats containers as disposable, so it would have recreated it as soon as it went away. The root of the issue was a bad logging config that we fixed on the next business day.
Are u running podman containers on Unraid or did you migrate away?
I migrated from docker containers on Unraid to using quadlets on RockyLinux. The Podlet utility helped a bit with taking an existing docker container and converting it to a quadlet. Also did thorough testing in a VM before swapping my server.
Interesting, just migrated away from Unraid myself. But chose Proxmox -> Debian -> Podman Containers instead. Any reason in particular you chose Rocky?
The security of Rocky is solid and RL 10 is supported for quite a long time. I’m also used to RHEL based systems at work, as we target Red Hat.
That being said, I wouldn’t recommend it for most people. SELinux can be annoying to deal with and can cause issues where it isn’t obvious that SELinux is the cause.
If I were to chose again, I would probably just pick Debian as most of my workloads are just running in containers or VMs. The only services running on the host are NFS and Samba.
Wtf I thought docker was foss. Fml man
Docker is foss. Docker desktop and docker sbx are not.
Are you sure about that? I see Copyright at the bottom (maybe the name) and is free only for personal tier, everything else costs money. Maybe some of the containers are open source per https://www.docker.com/products/trusted-content/open-source/ but I don’t see where it says anywhere that the actual software that is docker is OSS let alone FOSS.
The core of Docker is called Moby, which is open source on GitHub. So are docker-cli and compose
Ah, explains the whale!
It’s FOSS, but not Libre, and more close to open-core than to open source.
The version that is installable from the repositories of Linux distros is all open source. Docker itself, the container engine and runtime are all open source. Nobody cares about stuff like docker desktop or docker sbx, not only are they not critical to the software itself, they aren’t that useful or valuable.
I don’t mean Docker Desktop, I mean docker-cli and moby.
Just because something has a FOSS license and is open-sourced in some code forge doesn’t mean that it effectively respects some (or even all) of the four freedoms.
The version you get from Debian does respect all four freedoms.
It’s licensed Apache 2.0, which has been acknowledged as FOSS by the EFF.
Yeah, but I can use the license on my software but not respect that license at all… That’s what I mean. A license itself is nothing if the actions of the developer aren’t corresponding to it.
It can’t be FOSS but not Libre, the Free in FOSS means Libre. And it also can’t be FOSS but not opensource, of course.
No, Free means “Gratis”, or “Free as in Free Beer”, Libre means “Free as in Freedom”. That’s why FLOSS is recommended to be used instead FOSS, because the latter can be prone to confusion.
If you install the GUI it literally won’t let you open it unless you agree to their telemetry…
The GUI is not technically “Docker”. It’s made by Docker the company but it doesn’t use the same runtime engine, because it’s meant for non-Linux OS which don’t have it. It uses whatever the host OS has in place as an alternative.
Ah ok, that doesn’t affect me but still, what a bummer
It also works better sooo
Also, does Docker do rootless containers yet?
It does, but it seems like it’s still a bit of an afterthought. But it’s getting better.
Still tho, podman is fine and I like the project as an alternative to docker.
Docker rootless has been more stable for me than podman
Also it’s more secure and performant as it’s rootless and daemonless.
What exactly is your problem with Docker? It’s open source.
Also closed-source container images exist.
Haha idk, nothing really. Just found a lot of recommendations over Docker for podman.
Why would you use docker when you could use podman?
I use docker since it’s what I learned on a decade ago, and my nas that I started from supports docker bit not podman in the ‘app store’. I have three other machines running plain Debian, but I would want everything to work together, y’know? I’ve got a set-and-forget setup and I’d rather not break things without substantial benefit…
Plus everybody is like ‘it’s the same thing, no learning curve’ but then I start reading up on it and uhoh, learning curves :p
Plus everybody is like ‘it’s the same thing, no learning curve’ but then I start reading up on it and uhoh, learning curves :p
Exactly this. I tried podman, as a “container” newb, based on the idea that it’s a (better) drop-in replacement for docker, but it didn’t work. My quick attempts to resolve it went nowhere, and there were no instructions for the container I was trying to spin up for podman to explain the differences required.
So, in frustration, I decided to try docker and it just worked.
Good enough for me, for now. I still prefer the idea of not having a daemon running with root privileges, so I’ll likely move over to podman eventually, but I only have so much time to waste tinkering with my setup. And if it ain’t broke, don’t fix it.
In almost all cases podman will work as a drop-in replacement. Problems usually arise from podman not being rootful by default, which does make a difference in most scenarios that involve volume mounts, exposing ports or other kinds of host resource access. You can run podman as root and nowadays even docker as rootless (though at that point you might be better off with podman).
same, docker just works when I’m trying to use version pinning on half my containers so they don’t try using the wrong rocm version
Use docker rootless.
Just use the repositories in the terminal…
What?
I mean, install it from the repos through your package manager in the terminal, on your NAS.
With every update they warn that any changes made outside the UI may be overwritten (only data in user directories is safe). I have edited a couple config files over the years that have sticked, but they expect the system directories to stay ‘stock’ and warn of data loss or system malfunction if changed. And since it’s my nas it’s a lot of data to be going yolo on, even with backups. Wayyyy to much risk for almost no benefit.
Why would you use podman when you could
#!/bin/ksh daemon_execdir="/home/etebase/src" daemon_logfile="/var/log/etebase" daemon="/home/etebase/pyenv/bin/uvicorn" daemon_flags="etebase_server.asgi:application --host 159.100.247.89 --port 8000" daemon_user="_etebase" . /etc/rc.d/rc.subr rc_bg=YES rc_reload=NO pexp="/home/etebase/pyenv/bin/python3 ${daemon} ${daemon_flags}" rc_start() { rc_exec ". ~/.profile; ${daemon} ${daemon_flags} >> ${daemon_logfile} 2>&1" } rc_cmd $1Oh why you gotta talk so dirty to this little chatbot
Did you mean rc_start $1 as the last line of that script?
Idk, I was lazy and copied from here instead of going to one of my actual OpenBSD installations and checking. Could be different on other BSD style inits.
Some containers don’t like non-root setups.
There are still various incompatibilities between the two, and it becomes relevant if you need to work with any organization that has standardized on Docker-specific tooling.
Podman is a better choice.
What’s the benefit over Docker?
Rootless, better integrated with system, a bit faster and lighter on resources. Also it supports k8s style yaml configuration both ways and a lot of people are more familiar with them and they also provide some (minimal) interoperability.
Not requiring a service running in root context.
Not requiring a service running in root context.
I don’t think I’ve ever understood the distinction in this argument.
Isn’t systemd exactly that, a service running in root context?
I mean yeah you can technically run podman containers by hand as a non-privileged user but nobody does that, let’s be serious. Everybody uses systemd for management and autostart.
I really don’t understand how running a container through docker as a non-privileged user and dropping all caps is any different from doing the same through systemd + podman.
Tons of other services do that, ssh, CUPS etc.
If anybody can explain the difference I’d appreciate it.
While I’ve never used it myself, Docker Rootless mode seems to also allow this?
10 years too late.
It isn’t that easy to setup. Podman just works
At work, avoiding surprise licensing fees. If you ever have over 250 employees or over 10 million revenue, you owe a subscription.
At the home, easy orchestration with systemd
Isn’t that only for docker desktop?
Yes. Rancher desktop exists, btw. Just an fyi.
Edit: An open source alternative to Docker Desktop. It has most of the same features. Occasionally I’ve run into something that doesn’t work, but for the most part it’s just peachy.
It is! If you want to reduce exposure to this you really have to make sure mdm disallows installing it. The numbers trigger regardless of seats, and then you’re on the hook for the licenses for every employee using it.
So even if as a matter of policy you don’t use docker desktop, it’s possible engineers still do.
if you’re asking with regards to systemd orchestration, no. i love deploying containers as Ansible -> systemd -> podman.
No, they mean the license costs. I’m pretty sure, you only have to pay a fee for Docker Desktop…
my bad
Docker became a license nest despite actual devs using k8s like a normal person should.
Meanwhile podman gave us rootless containers, CDI, and quadlets which far outweighs whatever docker is limping to the barn with.
This! Podman rootless quadlets is so powerful and beautifully simple. Just look at that faaar superior security model and hos it doesnt even need a service to manage services because it just integrates natively with systemd I replaced my entire container layer from Rocker Swarm way back with K8s. Then it dawned on me I dont want the pods to move to another node by themselves anyway and then I just moved to Podman quadlets managed Ansible. Oh, and the podman pods are awesome as well.
Mom, i can i have podman?
Mom: we have podman at home.
Podman at home: rootless docker
y’all use containers still? I run my site with native installed software configured by hand like a TRUE sysadmin!
You’re that chain smoking black hat with a stack of computers, black out curtains several screens and not a single lightbulb.
This is why I don’t like Docker compared to Podman:

I literally yesterday dealt with that. There’s an option to just turn off Docker’s firewall manipulation so you can do it manually.
I had the same issue, but I just added my plain iptables rules to the DOCKER-USER table, which worked fine
Please elaborate…
Basically put:
{ iptables: False, Ip6tables: False }In /etc/docker/daemon.json
Ngl after trying out Rootless Podman on my system (I was playing with Distrobox) I kinda wanna switch my whole Homelab to it, I’m just lazy, afraid the move to rootless with blow up everything and have zero fucking free time.
I am running my entire homelab from podman quadlets (systemd managed podman containers) and it’s honestly very dope. Podman gets a bad rap for being second tier to docker but they legit have a bunch of awesome features for Linux users specifically that make it way nicer. Using systemd for docker status can add some misdirection occasionally, but having the logs from containers directly in journalctl alongside the rest of my system logs is amazing
i plan to set up my stuff like that as well, just don’t find time :/
I’m intrigued a LOT by Podman but also I’m already running some Docker stuff and it’s working.
I’d really like some guides on how to switch over and what all that entails, that isn’t written like I have 13 cloud certificates and this is another day at the office LOL.
So, 100% skill issue on my part.
In great news though: OpenMediaVault has Podman support in its GUI now! Love them.
I choose to use podman over docker because look at those cute seals 🥰
Also a solid technical reason for openSUSE
They look like a water type dugtrio.
i genuinely run all my shit bare metal
Hopefully none of those things have dependency version conflicts
they do quite regularly
🤘
Home sweet home
You_guys_use_docker?.jpg
That’s what I was thinking. I’ve barely ever understood it for deployments for large companies (even then I disagree, I think it’s added overhead just to bypass poor processes) but at home? Nah, install everything together.
Adding my voice: Podman is great