I switched from Docker to Podman and it fastened issues I did not know I had


Docker is a mainstay within the self-host neighborhood as a result of it gives a fast, simple option to arrange containers and self-host providers. However, there are some things about Docker that pushed me to search for an alternate.

Ultimately, I finished utilizing Docker in favor of Podman, a totally free and open-source container engine.

What is Podman?

A container engine like Docker

At its most elementary, Podman is a container engine very like Docker. It is suitable with OCI photographs, which suggests it may well fetch and run photographs from Docker Hub.

The similarities do not finish there both. The command-line instruments are fairly related too. Podman run, podman ps, and podman construct will all appear very acquainted to anybody that has used Docker earlier than.

However, it’s the variations between Podman and Docker that pushed me to change fully. The massive one is that, not like Docker, Podman would not run a root daemon. By default, every container runs below the person account that began it. Podman additionally has “pods,” which allow you to launch teams of containers collectively.

Rootless Podman sidesteps a giant firewall downside

Docker publishes ports round UFW

Unlike Docker’s default setup, Podman runs rootless except you are logged in as root or use sudo. That prevents one critical concern with Docker: It ignores your firewall settings.

Docker’s root daemon will bypass UFW and write its own NAT and forwarding guidelines in iptables. Because these guidelines are utilized earlier than UFW is within the loop, Docker functionally ignores UFW fully. You may even run ufw deny 8080 (a typical port folks use with Docker) and the port would nonetheless be open.

There are methods to forestall that concern, however I do not like that the default conduct is unsafe.

On the opposite hand, Podman would not usually have the permissions to edit the firewall guidelines. If you do one thing with a port utilizing Podman, it will be handled like a socket created by an strange person course of. UFW guidelines apply precisely as you’d anticipate.

Rootful Podman will nonetheless bypass a firewall like Docker, however that solely occurs whenever you run as root or with sudo.

Rootless is safer usually

Besides the precise concern with the firewall, rootless is a greater safety observe usually. If ever the container is compromised in some way, not operating as root provides an attacker yet one more impediment to beat.

Quadlets and systemd change the Docker daemon

Every container is an strange systemd service

A Podman Quadlet.

One of the largest issues folks encounter when leaving Docker is the lack of the daemon that retains containers operating. Podman has an answer for it: Quadlets.

A Quadlet is a small configuration file that tells systemd easy methods to deal with the container. Once the file is written, you should use systemd to handle your Podman containers precisely like another utility in your server. You can arrange autoboot and outline auto-restart insurance policies. As with most functions, logs are dealt with by journalctl.

Automatic updates are as simple as including a line to the Quadlet (AutoUpdate=registry) and enabling the Podman auto replace timer.

You ought to run loginctl enable-linger to your person in order that your containers begin at boot with out you logging in and proceed operating after you log off of your SSH session.

Moving from Docker to Podman

Most Compose information require little to no tweaking

VS Code Containers view showing running containers and Docker resources.

If you need to begin utilizing Podman rapidly, the podman compose command is your greatest guess. It permits you to use present Docker Compose information, and most of the time they’re going to work instantly. Sometimes they require minor tweaks, however on stability, the method is fairly simple.

Podman compose is a wrapper, so you may want docker-compose or podman-compose put in for it to work.

As a long term resolution, it’s also possible to convert Docker Compose information into Quadlets. The podlet software, which you put in individually, handles that conversion course of routinely—present a compose file, run the command, and also you get functioning Quadlet information out the opposite facet. It would not help each Compose choice, however it handles many of the arduous elements.

For container-to-container communication—a vital operate for a lot of apps and providers—place your providers in a single pod.


Rootless Podman with Quadlets is the safer selection for many Linux homelabs

Podman is barely completely different from Docker, and the transition wasn’t with no few hiccups. However, the payoff was vital. I’ve used systemd for years, and I want managing containers that option to Docker’s system. The rootless default conduct is a notable safety enchancment over the “rootful” Docker default.

And the migration course of wasn’t even that tough. Most of the Docker Compose information I used to be utilizing ran with no downside utilizing podman compose. Those that did not had been both simple to repair or labored as soon as podlet transformed them into Quadlets.

Rather than commit fully, strive operating Docker and Podman facet by facet for some time to see the way it goes. Besides the preliminary studying part, which solely lasted about half-hour, I have not seen that Podman is any tougher to make use of than Docker.



Source link