3 ms·
Show HN: GUI Applications in Podman on Wayland
- spinachsalad 5y agoHaven't you just reinvented Flatpak? ;)
- moody5bundle 5y agoFlatpak with Dockerfiles and yaml config! :)
- Filligree 5y agoIs this an advantage?
- aaomidi 5y agoI'm thinking of how this could be used on Windows systems. But honestly it's just really cool.
- ayanamist 5y agohttps://en.wikipedia.org/wiki/VMware_ThinApp https://en.wikipedia.org/wiki/VMware_ThinApp
- moody5bundle 5y agodepends on your use case. I wanted a way of removing network access for my text editors and starting ephermal firefox instances that are completely independent from each other. Its just an easier way to hack around an application tbh.
- deknos 5y agowell, building stuff with flatpak is not THAT intuitive. no package format before docker was from my point of view. on the other side, packaging also cleans up and docker-insides often are not cleaned up :D
- yewenjie 5y agoI'm curious, how do you limit memory or CPU resources in a regular linux system for a process?
- aaomidi 5y agoCgroups For example, systemd integrates with cgroups and you can limit resource use for services started with it
- xorcist 5y agoman ulimit Not sure what constitutes a regular Linux system but apart from the shell command the underlying ulimit syscall getrlimit(2) is in the kernel itself. One can set hard and soft limits on a per process granularity. Normally each service has a dedicated uid and limits as well as nice levels are set in /etc/security/limits.conf which is read on login sessions by pam_limits. This is in every bsd- and posix-like system and some of the soft limits have standardised signals assigned to them. The man page has all the details and is easy enough to understand.
- cranekam 5y agoulimit on Linux doesn’t support limiting RSS, only VSZ. I’d argue that limiting RSS — i.e., how much of the process in main memory — is more aligned with what someone wants than how big its virtual address space is, which can easily be distorted by e.g. mmap()ing a huge file in. IME trying to restrict by VSZ just leads to surprises when malloc() fails at surprising times. cgroups are a much better way to go.
- vanous 5y agoI have been looking for a way to replace"singularity" (now called app-containers). Is it possible to use podman to run a cli program inside podman container and it would run the program in the container but use local files to work with?
- moody5bundle 5y agothat is exactly what this is intended for :) look at this dockerfile: https://github.com/mody5bundle/capps/blob/main/container/sandbox/bash.dockerfile https://github.com/mody5bundle/capps/blob/main/container/san... and this "config" lines https://github.com/mody5bundle/capps/blob/aec6a118139c2008c3552763604cb55d197f10f3/config.yml#L130-L143 https://github.com/mody5bundle/capps/blob/aec6a118139c2008c3... this will start a cheap "sandbox" aka a gnome-terminal window with its own filesystem and process tree. you just have to change the config file to mount a volume on the paths you want and maybe tweak the image to your likings :)
- vanous 5y agoAwesome, thank you very much, I will give it a spin!
- deknos 5y agoThis looks promising. Now you just have to find a way to tunnel/interface the xdg-standards and you can replace flatpak...