11 ms·
Podman 4.2.0
- the_duke 4y agoWasn't podman mostly C at some point? Did they rewrite it in Go?
- ChefOnSec 4y agoI've did a bit of reverse searching. They've used Go all the time[1] [1](https://github.com/containers/podman/tree/3d0100bb44834d079ad0e2c7b9c264a3c5ec131e https://github.com/containers/podman/tree/3d0100bb44834d079a...)
- nezirus 4y agoThey were first to push crun[1], in place of runc, that is your C code in the stack :-) [1] https://github.com/containers/crun https://github.com/containers/crun
- Honiix 4y agoThe change log is endless ! I'm specifically interesting by the new support of Gitlab Runner !
- BossingAround 4y agoThis looks great. Now if only KinD supported Podman!
- encryptluks2 4y agoMinikube supports rootless Podman. Both are Kubernetes projects, but I find that Minikube appears to be getting more maintenance and is easier to mimic a production cluster for testing.
- moondev 4y agohttps://kind.sigs.k8s.io/docs/user/rootless/ https://kind.sigs.k8s.io/docs/user/rootless/
- BossingAround 4y agoI'm aware, wasn't able to make it work the last time. The support is still experimental.
- daoistmonk 4y agokind works fine with podman: KIND_EXPERIMENTAL_PROVIDER=podman kind create cluster https://kind.sigs.k8s.io/docs/user/rootless/ https://kind.sigs.k8s.io/docs/user/rootless/
- threatofrain 4y agoThis version of Podman is blazing!
- notThrowingAway 4y agoThis version contains the answer to everything.
- deleted 4y ago[deleted]
- encryptluks2 4y agoI love this, but one challenge I've found is podman kube play had issues with named volumes and `keep-id`. Hopefully those are fixed in this release. I guess I'll find out shortly.
- robinhoodexe 4y agoDoes anyone have experience “migrating” from docker to podman on a somewhat large scale? I am starting a new job soon in a DevOps role where the devs use both podman and docker and although the resulting images are the same, using two tools where one would suffice does not seem optimal. For context, it is a medium-sized (~40 devs) commodities trading company running some hundred applications in azure k8s but considering moving to on-prem k8s.
- encryptluks2 4y agoIf you want to do a straight migration you can start the socket unit and expose it via the DOCKER_HOST environment variable and use the standard docker tooling or use podman-docker to make it seamless. As long as you make no other changes everything should just work. Where people frequently run into issues is when they want to utilize the rootless feature, and that definitely requires adjustments and work.
- robinhoodexe 4y agoRootless is definitely one of the major selling points for using podman over docker, especially for local development.
- Lutger 4y agoIsn't there support for rootless docker these days as well?
- 5e92cb50239222b 4y agoI never used it, but have seen separate "rootless" images many times. Seems like you have to build a separate image for rootless Docker? podman runs regular images under an unprivileged user just fine.
- plonk 4y agoYou don't need a separate image. You can run a script to install a rootless systemd service that starts the Docker daemon. You just point the Docker client to that rootless daemon's socket and do things as before. You'll need some configuration if you want to expose system ports (below 1024).
- bongobingo1 4y agoBig fan of Podman. Technically every time I have tried to push it into my production workflow I've hit some snags, mostly around networking and some volume stuff but those snags are getting chipped away each release. The last time I did a strong test flight was around 3.X, so probably about time to try again, 4.0 was a big release. I like the integration with systemd and bringing "pods" out of k8. I like the "they're just processes" philosophical perspective and more "linux tech" focus of the team - i.e. cgroups v2 exists, lets use it. I would like to see some minor UI stuff such as compressing buildah stage output like docker buildx does but it's understandable why that isn't there (yet?). I think my only remaining quibble is getting true remote addresses when using rootless networking.
- kodah 4y agoYou can use podman with buildkit, it's just kind of a pain because you have to do it manually. It is missing some nice to have feature integrations with buildkit. The instructions are fairly clear: https://github.com/moby/buildkit https://github.com/moby/buildkit
- lima 4y agoThis really just means using rootless libcontainer (i.e. the Docker machinery) inside podman, it's not a native integration.
- eriksjolund 4y agoI haven't tried it out, but shouldn't you be able to detect the true remote address by using a socket that has been passed in via socket activation?
- eriksjolund 4y agoThe remote address is available when running a socket-activated container with rootless Podman. I verified it in a test.
- gerty 4y agoWill this eventually make it to RHEL8? Today it's at 4.0.2.
- encryptluks2 4y agoI wouldn't count on it unless you add some extra repo. RHEL releases are historically behind when it comes to software, which is claimed to provide more stability, but often older kernels in RHEL simply will not support the new underlying functionality. I am hopeful that if Podman ever has to make the decision to adapt at a modern pace with new software releases, or constantly try to backport fixes and code for old software, that they'll choose the modern approach.
- gerty 4y agoRHEL 8.6 upgraded podman from v3.3 to v4.0.2, so v4.2 is not outside the realm of possibility in the next release. Since podman development is driven by Red Hat, I feel that podman upgrades get quite some leeway... Very impatient to test out the play kube functionality managed by systemd.
- bonzini 4y agoThis is not really correct. First, some software is updated frequently in RHEL, including podman. RHEL 8 was released in 2019 and it has podman 4.0.2 from earlier this year. Second, even software that isn't updated often, or at all, in the base system might have newer releases available as modules. For example there are recent versions of Python in RHEL 8, with just the basic runtime so that you can use pip to install more packages. Third, the RHEL kernel is updated much more than the corresponding LTS releases. The RHEL 8 kernel is closer to 5.15-ish than to the nominal 4.18 release from which it was forked. Pace for backports has slowed down a bit, but there's interest in keeping the kernel up to date because people are running RHEL 9 containers on the RHEL 8 kernel.
- gertrunde 4y agoGiven the module streams functionality in the package system in RHEL 8+, it's fairly plausible that it would be introduced using that path. (Currently, there are 5 'container-tools' module streams listed, with podman versions including 1.0, 1.6, 3.0, 4.0 in stable streams, and 4.0.2 in the rolling stream.)
- Hallucinaut 4y agoI was looking at this just last night and the story with Ubuntu is horrible. That's essentially going to be stuck on v3.4 for ten years because it's "a lot of work" to get into that distribution. You'd think an entity the size of RedHat trying to take the reins from Docker would understand that this is an investment they have to make to make it a first-class replacement. I also installed it on Windows to see how the WSL engine works but now it conflicts with my existing v3 Podman installation on Ubuntu 20.04 in WSLv2 so I guess I'm out of luck. Also may be of interest to people here but Podman desktop had a release yesterday. It's pretty primitive and I couldn't get it to work to use my existing auth.json but it's there. It was a pretty frustrating experience when all I wanted was to be able to "podman login" to a local repository so Jib would pull down base layers correctly.
- Iolaum 4y agoRed Hat has no official affiliation with Canonical who make Ubuntu. If you want to test podman you 'll have better luck using an OS from the Fedora ecosystem where Red Hat has affiliations and is actively contributing. Since you mentioned Windows I 'd suggest trying something like this [1] or this [2] [1]: https://github.com/yosukes-dev/FedoraWSL https://github.com/yosukes-dev/FedoraWSL [2]: https://github.com/WhitewaterFoundry/Fedora-Remix-for-WSL https://github.com/WhitewaterFoundry/Fedora-Remix-for-WSL Disclaimer. I am not using Windows to test above solutions anymore. More than a year ago I used [2] but from a casual look maybe [1] is better now.
- burmanm 4y agoPersonally I followed the rootfs way of installing Fedora to WSL2. It was simple enough and worked fine (including podman). I found no reason to use external tools / scripts / modified distros. Sadly, some anti-cheat tools in games still refuse to work with WSL2 (they hate Hyper-V, I guess it's been used as attack vector), so back to VMware Player on my personal workstation and using terminal to open Linux shell.
- mwcampbell 4y agoI wonder why Fedora doesn't provide an official WSL package on the Microsoft Store as other distros do. My guess is that they feel that the WSL kernel and init diverge too far from the Fedora kernel and systemd. Can anyone from the Fedora project comment on this?
- make_me_rich 4y agoIs anybody able to install it on MacOs with brew? Seems to be broken: „Error: podman: Failed to download resource „podman_bottle_manifest“
- jhickok 4y agoI just updated from 4.1 to 4.2 on my M1 using Brew without an issue.
- eriksjolund 4y agoI like this Podman feature: Socket activation of containers Advantages: - Faster network. Rootless Podman will run with native network speed. Normally rootless Podman runs with reduced network speed due to the performance penalty that comes from using slirp4netns. - Improved security as you can disable the ability to establish outgoing connections with --network=none. The container can still communicate over the socket-activated socket with a client that has connected via the internet. I contributed a Podman socket activation tutorial: https://github.com/containers/podman/blob/main/docs/tutorials/socket_activation.md#socket-activation-of-containers https://github.com/containers/podman/blob/main/docs/tutorial... and I wrote two blogs about the security advantages https://www.redhat.com/sysadmin/socket-activation-podman https://www.redhat.com/sysadmin/socket-activation-podman https://www.redhat.com/sysadmin/podman-systemd-limit-access https://www.redhat.com/sysadmin/podman-systemd-limit-access Docker does not support socket activation of containers. (Docker only supports socket activation of the Docker daemon) Edit: A clarification about the network speed. The improved speed is about the communication that passes over the socket-activated socket. This communication does not pass through slirp4netns so it has the same performance characteristics as the normal network on the host.
- the8472 4y agoThat's neat and quite a unixy solution but still fairly limiting. Are there any plans for a hybrid solution where most of podman runs as non-root via userns but invokes a suid helper to setup the network?
- eriksjolund 4y agoNot exactly what you are asking for but there is a Systemd feature request to add Connect= setting to service unit files. https://github.com/systemd/systemd/issues/23067#issuecomment-1098115045 https://github.com/systemd/systemd/issues/23067#issuecomment... (That could a be cool feature) Also interesting would be to fix the security considerations of using bypass4netns: "However, it is probably possible to connect to host loopback IPs by exploiting TOCTOU of struct sockaddr * pointers." There seems to be an implementation idea for how the problem could be fixed: https://github.com/rootless-containers/bypass4netns/issues/21 https://github.com/rootless-containers/bypass4netns/issues/2...
- wdb 4y agoNow if Gitlab.com only supported leveraging Podman in their runners.
- rhatdan 4y agoPodman is supported as a gitlab-runner now, as I understand it. https://gitlab.com/gitlab-org/gitlab-runner/-/issues/29108 https://gitlab.com/gitlab-org/gitlab-runner/-/issues/29108
- deastman 4y agoDarren here - PM for GitLab Runner. At this time, we aren't considering adding Podman to GitLab SaaS Runners on Linux. I created this issue, so please add comments there so we can continue the discussion. https://gitlab.com/gitlab-org/gitlab/-/issues/370522 https://gitlab.com/gitlab-org/gitlab/-/issues/370522
- spprashant 4y agoAnyone know a good resource for understanding the fundamentals of containers, in particular, how it persists state? Also maybe how different products (kubernetes, podman, docker) fit into this space? Thanks in advance!
- EddySchauHai 4y agoMaybe articles like https://www.infoq.com/articles/build-a-container-golang/ https://www.infoq.com/articles/build-a-container-golang/ could help? Basically learn how to build a simple one.
- rubyist5eva 4y agoI love Podman so much. It's seamless integration with systemd is a killer feature, as well as being able to generte Kubefiles. My main problem used to be feature parity with docker networking, but that seems to be mostly resolved since 4.0. Trying to convince my team to use podman instead of docker (even though I've been using it myself primarily for months without issues), that's another story.
- jtreminio 4y agoNot a Podman or Docker-specific question/complaint, but is anyone working on a solution around UID/GID remapping between container and host? Not the "solution" offered by user namespaces, because those can only do a 1:1 remap, but an "anything any user writes inside the container is owned by the host user". In other words, if host UID 1000 runs a container that has UID 100, 101, 102 and they all write files to a mounted volume, it would be great if all file writes were attributed to the host UID of 1000. Instead, if user namespaces are configured correctly they would attribute to UID 1000, 1001, 1002 on host.
- rhatdan 4y agofuse-overlay has some support for this, but it is fairly experimental. Basically it allows mapping of all files to a single UID, and then stores container owners/permission in XAttrs. When fuse-overlayfs exposes the image to the container process it exposes the xattr user/group and permissions.
- jmholla 4y agoYou can use ACLs for this.
- vxa_victor 4y agoHow does Podman Desktop compare to Rancher Desktop?
- emptysongglass 4y agoNo Kubernetes cluster, which is kind of the whole point of RD.
- sytse 4y agoVery cool to see Podman Desktop. This seems a replacement for Docker Desktop that is now organizations with more than 250 employees or more than $10 million in revenue https://www.infoq.com/news/2021/09/docker-desktop-subscriptions/ https://www.infoq.com/news/2021/09/docker-desktop-subscripti... Also cool to see GitLab Runner support as the first feature mention.
- emptysongglass 4y agoIt is, however, missing the 1-click Kubernetes feature of Docker Desktio.
- dirtsoc 4y agoI really like the ideas behind podman but they were not able to get enough feature parity with docker fast enough for my org. We use rancher desktop now for local development with Docker underneath. It would be cool if they added podman support in Rancher Desktop.
- djinnandtonic 4y agoRead the release log for Funny Number jokes, came away disappointed