12 ms·
Podman 4.0
- bargle0 5y agoIs it still a PITA to make RHEL containers with Podman?
- tgz 5y agoPodman is a docker that was done right.
- fkeith 5y agoIt's funny how Podman API is so similar to Docker (well, I guess it's more about OCI specs) that you can just "alias docker='podman'" and completely forget about it
- eatonphil 5y agoI'm still on version 3 but Podman is easier to use than ever. Kinda random: it even supports `podman build` with `-v` so you can volume mount in during a build. I didn't even think about it (I have `alias docker=podman` on my machine) until I pushed `docker build -v $(pwd):/x` to Github Actions and Docker failed on it. And apparently Podman has supported this for years while Docker hasn't :shrugs:. https://github.com/moby/moby/issues/14080 https://github.com/moby/moby/issues/14080
- vbezhenar 5y agoWow I just struggled yesterday without that feature. Can’t wait to switch to podman.
- maxloh 5y agoHow did you get podman instead of docker installed in the first place?
- eatonphil 5y ago`dnf install podman` probably? I can't remember.
- dmitris 5y agoalternatively `sudo dnf module install -y container-tools` https://podman.io/getting-started/installation https://podman.io/getting-started/installation
- freedomben 5y agoOn RHEL 8 docker didn't support cgroups v2 so the OOTB `docker` package installed podman and aliased it to docker. IIRC Fedora 30 and 31 did too? I don't remember exactly. You can run docker pretty easily on RHEL 8 but you have to downgrade cgroups in order to do so. Plenty of guides out there now.
- CrLf 5y agoCurrent Docker supports cgroupsv2 as well.
- freedomben 5y agoYes current docker does, but it didn't at the time RHEL 8 came out. The question I was responding to was "How did you get podman instead of docker installed in the first place?" and GP mentioned `dnf`, which is a RHEL/Fedora thing, so I think it's a pretty reasonable theory.
- qbasic_forever 5y agodocker supports some volume mounts while building, it's part of the buildkit backend and is used for mounting secrets during builds. It is very poorly documented and hidden behind the buildkit buildx command. Check out the RUN --mount= section here: https://github.com/moby/buildkit/blob/master/frontend/dockerfile/docs/syntax.md#build-mounts-run---mount https://github.com/moby/buildkit/blob/master/frontend/docker...
- saxonww 5y agoIt really is poorly documented. If you don't know it exists, it's difficult to find the document you've linked. I do know it exists and I still have a hard time finding it; it's barely mentioned (or not mentioned) in the regular Docker documentation, which is where most people will be looking. Buildkit is not exclusive to docker buildx though. You can use this with regular docker build as long as you've set the DOCKER_BUILDKIT environment variable, as noted in the document. You can also forward this to docker-compose, though there's another COMPOSE_DOCKER_CLI_BUILD variable you must set for that. That said, it looks like this extra frontend syntax is Docker-only, which means you shouldn't use it unless you're committed to the Docker tooling and ecosystem.
- qbasic_forever 5y agoYeah it's a royal mess right now unfortunately. It kind of seems like most of the work on docker's developer experience stopped in the last few years as the company went through turmoil and different ownership changes. Hopefully some day they sit down and really clarify what the 'golden path' is for a developer using docker today. Buildkit is really cool and can do a lot of nifty things once all these new features are enabled.
- 2OEH8eoCRo0 5y agoNew Rust-based network stack. Support for Windows and OSX. Supports WSL2 backend. Looks nice! Hats off to the Podman team!
- tunesmith 5y agoAnyone know if this can be easily used in place of Docker Desktop for Mac?
- MindTooth 5y agoRancher Desktop[0] is one new kid on the block. Any reason for why you want to change? https://rancherdesktop.io/ https://rancherdesktop.io/
- kbd 5y agoPersonally I'd prefer to use open-source tools if possible. For Podman vs Rancher, what are pros and cons? If you only use Docker from the command line is there any reason to use Rancher?
- MindTooth 5y agoIf only podman, not really. Optiona are also lima and colima for a more native feel. Seemd version 4.0 is a nice release.
- saxonww 5y agoI spent about an hour with Rancher Desktop when I was really pissed off about the Docker Desktop licensing change. There were a few things that out of the box were a problem for me (note: really a problem with nerdctl/containerd): 1. nerdctl did not support registry mirrors for image pulls. This is an obvious blocker for some uses cases. 2. with Docker Desktop you can bind container ports to any interface on the host system, including e.g. ip aliases on localhost. It didn't seem to be possible with nerdctl using whatever VM backend Rancher is using. 2a. I'm not sure how this works today, but with Docker Desktop a `docker pull` can interact with a registry available on the host's localhost address (i.e. through an SSH tunnel established on the host). This worked with Rancher, but I believe I had to edit /etc/hosts inside the Rancher-controlled VM to point at a different IP address, whereas with Docker Desktop it just worked. I also seemed to recall needing to manually start things with Rancher, i.e. just having the app open was not enough for docker/kubectl/nerdctl to be ready to go. But I don't remember at this point. These are all (I hope) uncommon and weird use cases, but they are the sort of thing that will keep some people using Docker Desktop instead of an alternative. They are, for better or worse, the value add of Docker Desktop.
- crb 5y agoIf you want to learn about the history of the Podman project, you might enjoy my interview with Red Hat's container team lead and Podman's architect. https://kubernetespodcast.com/episode/164-podman/ https://kubernetespodcast.com/episode/164-podman/
- eatonphil 5y agoI first learned about and was immediately sold on Podman in 2018 when Dan Walsh gave a talk at NYLUG. I think this is the same talk: https://www.youtube.com/watch?v=riZ5YPWufsY https://www.youtube.com/watch?v=riZ5YPWufsY. Called "replacing docker with podman".
- warmwaffles 5y agoThanks, I'll check it out. I've been wanting a replacement to fill the `rkt` hole in my heart.
- szastamasta 5y agoGreat news. I hope it will now work with docker compose. Missing compose support was the only reason I had to ditch it in favor of Colima. But will try it out again now.
- eatonphil 5y agoI use it with docker-compose now and I'm running podman 3.4.4. I think you just need to install `podman-docker` on Fedora to get the docker socket. See: https://www.redhat.com/sysadmin/podman-docker-compose https://www.redhat.com/sysadmin/podman-docker-compose.
- maxloh 5y ago`docker-compose` is different from `docker compose` (with a space in between words). The former will be replaced by the latter in the long run. https://github.com/docker/compose-cli/issues/901#issuecomment-866573893 https://github.com/docker/compose-cli/issues/901#issuecommen...
- conor_f 5y agodocker-compose was really the paradigm shift I needed when it came to containers and now I'm whole-heartedly on board with containerization. No reason something like the compose syntax (or similar) couldn't be a common, shared front-end to all container solutions, but until that point, I'm going to be sticking with Docker purely for certainty that docker-compose functions as expected.
- SahAssar 5y agoI'm probably just missing some fundamental knowledge, but why does podman need it's own network stack? Doesn't linux include functionality for things like virtual networks, bridges, virtual networks and similar? EDIT: the second "virtual networks" meant to say "virtual interfaces"
- metadat 5y agoOut-of-the-box Linux doesn't handle container networking in a default fashion, because there are many common configurations and techniques available to obtain different effects and results for the exact nature of each network being attached or created.
- freedomben 5y agoWhen they say "network stack" they don't mean their own implementations of TCP and UDP like you would for an OS (like linux). They mean the various pieces that the container runtime has to implement. See CNI[1] for more information. [1]: https://www.cni.dev/ https://www.cni.dev/
- SahAssar 5y agoSo it's the "compiler" for a CNI spec into a configuration for a linux network namespace?
- freedomben 5y agoYeah I think that's a reasonable way to think of it. When a container (or Pod) gets created it needs a handful of network stuff setup, from creating the virtual network interfaces, setting up route tables. nftables/iptables rules, assigning an IP address, setting up NAT, configuring container-to-container networking, etc.
- SahAssar 5y agoThanks, that makes sense. I'd prefer it'd be called something else than a "network stack", but that's life.
- deknos 5y agodoes podman now support nftables and does not create legacy iptables anymore?
- topspin 5y agoThis release adds Netavark for container network configuration (in addition to the existing CNI stack support.) Netavark says "Support for iptables and firewalld at present, with support for nftables planned in a future release" So not yet, but planned.
- mfer 5y agoIt’s worth noting that existing CNI plugins use iptables. If something uses those it’ll end up using iptables. Getting those updated or replaced would be making transitions to something newer Disclaimer, I started Rancher Desktop
- nhoughto 5y agoIs there an eli5 or similar on the differences between podman / docker / rancher / others? Feels unexplained (at least for me), how do I know which to choose when and what are the trade offs? I recently went deeper on Rancher Desktop and it’s use of containerd vs dockerd backends and it is totally not obvious what you lose if not using dockerd and how you might fill the gaps. Feels like because docker established the space and put a bunch of related components together (cli, image building, image storing and container running) and other projects make difference choices it can be quite confusing to compare them.
- pydry 5y agomy understanding was that it was docker that doesnt need root or a daemon. i always thought it seemed wrong that it needed either of those to start with. in most other respects i think it's a drop in replacement.
- anthropodie 5y agoWhat you said is true. Other than those podman: - does not mess with your iptables unlike docker. Because of this docker can bypass firewall rules set by ufw - does not creates bridged networks
- freedomben 5y agoIf you use K8s or some other production container runtime, those are enormous benefits.
- mfer 5y agoIt depends on what you’re looking for. Most people use containerd as their backend to Kubernetes. Docker itself uses it. Podman uses a different engine. That may matter to some folks. There are also a bunch of tools that talk directly to the docker socket. There are a lot of varying use cases here. Disclaimer, I started Rancher Desktop.
- 5y ago
- maxloh 5y agoHow is it compared to nerdctl[0] (another docker compatible cli)? [0]: https://github.com/containerd/nerdctl https://github.com/containerd/nerdctl
- raesene9 5y agonerdctl is just a new client to target containerd. Containerd has been around a long time, it was originally part of Docker itself, but was separated out and is now a standalone project. Docker uses containerd as part of it's standard deployment. Containerd is a long running daemon (similar to dockerd), so that's where the difference lies in that podman (in it's default setup) doesn't have a long running daemon. The closest analogy to containerd in RH land is CRI-O.
- peachy_no_pie 5y agoPodman uses runc as the default container runtime. Nerdctl uses containerd. There are probably other differences but that's a substantial one imo.
- raesene9 5y agoI think that's mixing apples with oranges really, as containerd uses runc as well. nerdctl is a client app which speaks to containerd, which is a long running daemon. podman uses a different architecture (no long running daemon) Both projects use runc to actually launch the containers.
- mroche 5y agoThis depends on the platform you're using. On Fedora and RHEL 9, the default runtime is crun. On RHEL 7 and RHEL 8, the default is runc. In any case they can be swapped as needed. https://github.com/containers/crun https://github.com/containers/crun
- Macha 5y agoPodman has been a longer lived project. It's supposed mostly by Red Hat, which may be a plus or minus in your view. nerdctl re-uses more of moby's (formerly Docker CE) underlying tech. Podman has some nice convenience features to generate kube yaml or systemd units.
- eriksjolund 5y agoI like this Podman feature: Support for socket activation Podman will pass on the socket-activated socket to the container. I wrote a small example demo for setting up socket activation with systemd, Podman, and a MariaDB container: https://github.com/eriksjolund/mariadb-podman-socket-activation https://github.com/eriksjolund/mariadb-podman-socket-activat...
- mikepurvis 5y agoOverall the integration story between podman and systemd is way, way better than with Docker. And that's in both directions, from using the host's systemd to start and manage containers, but also for running systemd within podman containers.
- freedomben 5y agoI would definitely expect that given the history of systemd and docker. IIRC difficulty Red Hat team had with integrating systemd and docker was one of the reasons why they started Podman rather than continuing to push everything upstream to docker. The docker team didn't want docker to have to accommodate systemd and refused some contributions that were important for a good integration.* *There's still some bad blood out there about it, so I just wanted to make explicit that I'm not making a value judgment on docker's refusal. I'm not educated enough on the details to make a fair judgment. Sometimes you have to say "no" to features to protect your product.
- nunez 5y agoOne of the folks that wrote THE manual on how to get systemd to work with Docker works at Red Hat on podman, so that's not surprising at all.
- freedomben 5y agoThis is a great release, very exciting! When I worked for Red Hat as an OpenShift Consultant it was common to have developers super excited for using podman, but because the macOS story was poor they had to revert to docker. This removes a huge blocker for a lot of people!
- mindwok 5y agoI kinda feel bad for Docker. The prevailing wisdom seems to be that you shouldn't be using Docker anymore, use Podman. Often the reasons for this is that Podman is daemonless, supports rootless containers, etc. But I feel this is misplaced: - The Docker daemon is actually really useful. It can run containers as other users, perform a bunch of mounting and networking stuff you can't do as rootless (or at least requires some hacky workarounds), and can monitor/maintain your containers. Podman can do lots of this as well, but requires the use of systemd. So in those cases you've just swapped one daemon for another. - For most of my use cases, I don't really care about rootless. On servers I run all my docker containers as non-root anyway, and if I'm on a workstation I have privileges and don't need rootless. - Although Podman claims compatibility with Docker, I've always found issues with trying to use it even up to a few months ago, prior to this release. Mostly when trying to use compose, although it does improve every release. I basically just view the Docker daemon as an init system like systemd. It's a privileged daemon that runs other processes. But for some reason it seems to have been made into a bogeyman.
- zzzeek 5y agofrom my experience I often find myself waiting for a hung docker daemon to give me the answer to a query. I dont know much about how it works but it feels monolithic and fragile the way a single container seems to be able to hang the whole thing and I can't even do a "docker ps" to see what's going on. Podman doesnt have any issues like that, it responds quickly at all times regardless of individual container status in my experience.
- jiehong 5y agoOne thing that is actually nicer is that podman can run kubernetes pods from the kubernetes yaml file description (mostly) directly. This avoids having to use kubernetes in production, and something different (like docker-compose) in local. Being able to search in multiple container registries is very nice, and docker doesn't allow you to do that (to the best of my knowledge). It's very useful if you have a company container registry for example.
- mindwok 5y ago
- kosikond 5y agoI tried to migrate from Docker to Podman 3.4 recently, but just gave up. It just have still weird quirks, containers were exiting without any clear cause, fighting with SELinux... I could not manage portainer.io to get working... the docs are somewhat incomplete...Lack of support in Debian [1] means I can't easily migrate my SBCs either. I have Podman on my radar, will give it a shot next year, so far it still feels still quite bleeding edge. But kudos to red hatters for another major release! [1] Fully knowing there is v3.0.0 in repos for Stable, but switching to Testing just because podman?
- yonran 5y agoI also tried running a service in podman 3.4.2 on ubuntu recently, and I agree that it had a lot of rough edges e.g. ports that fail to publish when restarting a service, podman ps losing track of containers if you ran podman as User= in systemd. There are lots of command incantations that you have to learn when using rootless podman which are not clearly documented (loginctl enable-linger, sudo --user USER XDG_RUNTIME_DIR=/run/user/$(id -u USER) systemctl --user restart, usermod --add-subuids, podman unshare chown). Hopefully it becomes clearer over time.
- dang 5y agoRelated: Podman in Linux - https://news.ycombinator.com/item?id=28687229 https://news.ycombinator.com/item?id=28687229 - Sept 2021 (89 comments) How to Replace Docker with Podman on a Mac - https://news.ycombinator.com/item?id=28462495 https://news.ycombinator.com/item?id=28462495 - Sept 2021 (85 comments) Podman, the open source Docker alternative ported to M1 (Apple Silicon) machines - https://news.ycombinator.com/item?id=28429650 https://news.ycombinator.com/item?id=28429650 - Sept 2021 (147 comments) Migrating from Docker to Podman - https://news.ycombinator.com/item?id=28413470 https://news.ycombinator.com/item?id=28413470 - Sept 2021 (107 comments) Podman: A tool for managing OCI containers and pods - https://news.ycombinator.com/item?id=28376686 https://news.ycombinator.com/item?id=28376686 - Sept 2021 (184 comments) Podman: A Daemonless Container Engine - https://news.ycombinator.com/item?id=26101608 https://news.ycombinator.com/item?id=26101608 - Feb 2021 (241 comments) Transitioning from Docker to Podman - https://news.ycombinator.com/item?id=25165195 https://news.ycombinator.com/item?id=25165195 - Nov 2020 (268 comments) Podman and Buildah for Docker Users - https://news.ycombinator.com/item?id=21556894 https://news.ycombinator.com/item?id=21556894 - Nov 2019 (73 comments) Dockerless, part 3: Moving development environment to containers with Podman - https://news.ycombinator.com/item?id=20503061 https://news.ycombinator.com/item?id=20503061 - July 2019 (40 comments) Podman and Buildah available in RHEL 7.6 and RHEL 8 Beta - https://news.ycombinator.com/item?id=19005426 https://news.ycombinator.com/item?id=19005426 - Jan 2019 (50 comments)
- thecosmicfrog 5y agoHow's Podman's Apple Silicon (M1) support these days? Last time I checked - maybe 3 months ago - it was pretty rough.
- DoneWithAllThat 5y agoI tried switching to Podman for my Home Assistant install. One day it just stopped working - I forget the exact error, I believe it was networking related. Unfortunately I couldn’t find any reason why it broke or resources on how to fix it so I just went back to Docker. I really want to support Podman but this was a discouraging experience.
- DCKing 5y agoI really like Podman, and I'm happy to see this new release. This little nugget about non-released features makes me most excited though: > More features, including support for volume mounts from the host, are planned for Podman v4.1, so stay tuned for more updates. IIUC host volume mounts for podman-machine are the last major missing feature in Podman that would allow something like Podman Desktop Companion [1] to replace Docker Desktop on Windows/Mac for most use cases - if it works well. It'd be great to replace that nagging-for-updates and nagging-for-subscriptions with a completely open source replacement tool. (I'm sympathetic to the Docker team in need of a revenue source, but I'm really happy OCI containers on Mac and Windows can be made accessible without vendor lock-in). [1]: https://iongion.github.io/podman-desktop-companion/ https://iongion.github.io/podman-desktop-companion/
- gavinray 5y agoWhoa, thank you for sharing this. I was looking for a Docker Desktop alternative for Podman and found Cockpit but it's not the same. This looks awesome!
- kodah 5y agoEh, not the only thing. Podman is definitely well on it's way, but my team builds tooling that builds and orchestrates our development environments. When we switched from docker to podman we immediately noticed how slow our container based build stage had become. Podman lacked some caching layer that docker was automatically orchestrating as well as parallel builds (without build kit, and build kit isn't super simple to integrate). Once we integrated build kit it made our build times very similar, but this was only possible because we had tooling to orchestrate build kit on top of podman.
- throwaway894345 5y agoAs an aside, I recently tried to dabble with some BuildKit APIs and man that was one of the lowest quality Go codebases I've encountered. Probably the lowest hanging fruit would be documenting APIs. Podman (and IIRC Buildah) by comparison were clean, well documented, reasonable APIs were exposed, etc.
- benatkin 5y agoI'm not convinced Podman will be very popular going forward. There is multipass which can be installed on my M1 Mac with: > brew install multipass I can create a minikube container, or I can create an Ubuntu container and install microk8s.
- jdoss 5y agoPodman has been one of my favorite opensource projects in the most recent years. I have been using it since 1.x and it keeps getting better and better. It is one of the tools that makes me not totally hate containers and I use it all over the place. :) At my last job we used Fedora CoreOS with Podman + systemd (I did a talk about it at Fedora Contributor Conference [1]) and I released self hosted installer that ships a Ruby application inside of a Podman pod. You can check out the systemd units here [2]. Using systemd gets you all the dependency management so your App's services start in the right order which is pretty great! One of the cool things that I love about Podman is running everything inside A Podman pod. You get your own network namespace so you can launch a bunch of services on the same host without cluttering up your host's localhost. Here is a script I use to run Owncast on a Fedora Server [3]. I also have an script I gave my old coworker to launch all of his apps dependencies inside a podman pod [4]. If you are thinking about giving Podman a shot, check out the links and hopefully that can help you get started with or without systemd. [1]: https://www.youtube.com/watch?v=9qMSHaHGnoY https://www.youtube.com/watch?v=9qMSHaHGnoY [2]: https://github.com/forem/selfhost/blob/main/playbooks/templates/forem.yml.j2#L810-L1140 https://github.com/forem/selfhost/blob/main/playbooks/templa... [3]: https://gist.github.com/jdoss/ad87375b776178e9031685b71dbe37cf https://gist.github.com/jdoss/ad87375b776178e9031685b71dbe37... [4]: https://gist.github.com/jdoss/25f9dac0a616e524f8794a89b7989e9f https://gist.github.com/jdoss/25f9dac0a616e524f8794a89b7989e...
- withinboredom 5y agoSincere question: is “cluttering up localhost” actually a thing?
- jdoss 5y agoIt might not be. It maybe a workflow thing and a poor choice of words on my end. I have a few apps running on my workstation that I run in Podman pods that have similar service deps (PostgreSQL and MQTT etc). I don't have to worry about making sure my apps are pointed at some random ports for their services and I don't have to deal with changing the ports per service in my application stack. I can just launch them in a pod and get some nice isolation in the pod's network namespace and use the defaults. I think it is a nice pattern to use for local development. I hope that clears things up.
- ei8ths 5y agopodman is awesome, looks like a good set of changes and improvements.
- cedricgle 5y agoI am not sure what is Netavark about: are they deprecating the CNI convention and rolling anew one or is it some-kind of a new layer of abstraction ?. What if I wanted to: keep using Cilium with Pod in the future, or having a chains of multiple CNIs ?.
- ilovecaching 5y agoThe thing I don't like about podman and buildah are the names... they make sense as contracts, but they also sound like joke names. Hard to sell to management why we should switch from a trusted name docker to something that sounds like its a misspelling of builder and a superhero who's only power is deploying Kubernetes clusters.
- mshekow 5y agoI found getting started with Podman on Windows is utterly confusing: 1) Podman has two documentation entry points (https://docs.podman.io https://docs.podman.io and https://podman.io/getting-started/ https://podman.io/getting-started/) because... ? It is confusing to the user at first. It makes more sense to have everything in one place. 2) Podman does not _actually_ offer binary releases (but claims to do so here: https://podman.io/getting-started/installation#windows https://podman.io/getting-started/installation#windows and https://github.com/containers/podman/blob/main/docs/tutorials/mac_win_client.md https://github.com/containers/podman/blob/main/docs/tutorial...) because... ? They want me to compile it myself? 3) The Windows installation tutorial links to another article (https://www.redhat.com/sysadmin/podman-windows-wsl2 https://www.redhat.com/sysadmin/podman-windows-wsl2) that is, by today's measurements, _very_ old, because... ? I cannot imagine that things have not changed since then, I refuse to believe it :D From what I understand, Podman will become an _actually_ easy to use and viable solution to Docker for Desktop once Podman 4.1 has been released, and we have host volume mount support, which is a must-have feature for development.