5 ms·
Several times I tried to use podman on mac to replace docker tooling, the idea of daemonless-rootless is enticing. However, there's always things that doesn't w
by wejick 3y ago
Several times I tried to use podman on mac to replace docker tooling, the idea of daemonless-rootless is enticing. However, there's always things that doesn't work or work differently on podman that make it not easy to work in team that predominantly using docker.
Usually it's about networking setup or compose compatibility.
Maybe someone encountered similar situation can share your experience.
- rgovostes 3y agoI had the same experience for a while, and was a little bitter about repeatedly taking them at their word that you could transparently `alias docker=podman`, even when Podman 4.0 didn't even support volume mounts from the host without jumping through hoops. I suggested that the team document or at least label compatibility issues so users are informed about them, but they rejected the idea[0], recommending instead that users keep abreast of changes to a 35 page troubleshooting file. That said, I've been living on it full time for a few months, and it's working well. I'm using the Docker CLI with Podman providing the backend implementation. Biggest caveats: Mounting volumes from the host is still a little limited. It doesn't play nice with giving docker.sock back to Docker Engine (wontfix[1]). The --platform flag was broken but should be fixed in 4.6. 0: https://github.com/containers/podman/discussions/14430 https://github.com/containers/podman/discussions/14430 1: https://github.com/containers/podman/issues/18784 https://github.com/containers/podman/issues/18784
- laserlight 3y agoI was also a victim of “just alias docker to podman” advertising. I couldn't run even a single container with podman on my Mac. I'm happy to have given up early with their BS.
- asdafa 3y ago`BS` is a bit unfair. It is true that podman-desktop is a bit rough around the edges still, but it is in no worse shape than docker-desktop used to be when it was a year and a half old project. With the release of podman 4.6.0 a lot of the issues have been sorted out, podman-desktop is still shipping engine 4.5.1 at the moment, but a new release should be coming out soon. I'd suggest you give it another shot.
- kobalsky 3y agoit’s bs because they have elected to not maintain cli compatibility on many areas. not because they “haven’t gotten there yet” but because they don’t agree with docker. they converted into technological amish that think the one true cli is not the current one.
- lttlrck 3y agoAside from desktop, at one point maybe two years ago they were pushing the alias, and it didn't work on Linux. It was BS.
- viraptor 3y ago> podman on mac to replace docker tooling, the idea of daemonless-rootless is enticing I'm confused by this one. You're already running a VM in order to use containers on a Mac. What does the daemonless approach inside a container give you? That feature works great on Linux servers for me, but I'm not sure what's the point outside of that.
- rr808 3y agoI work in a big corp where people aren't allowed root access under any circumstances. Podman works for us because infosec guys are happy.
- viraptor 3y agoFor the Mac context, you're running a VM as root before you even touch podman/docker. I'm confused how that's different.
- LeBit 3y agoAre you sure the podman machine's VM is running as root?
- viraptor 3y agoKinda, a bit, it's hard. So podman will need virtualisation and networking permissions to do its job. Also the directory mapping seems to work without extra confirmation. At that point, who needs root? You control the main user`s files, networking, and can effectively hide any process from easy inspection by using virtualisation.
- rr808 3y agoI'm talking servers. We aren't allowed to run either on workstations.
- deleted 3y ago[deleted]
- usr1106 3y agopodman is supposed to be more secure than docker. How do they reach improved security? By limiting access to the system that could be dangerous if misused. Obviously with additional limitations comes incompatibility. If your image tries to do something that is no longer allowed the same way, it won't work the same way as before. Compatibility exists only for images that don't do anything potentially dangerous. Ironically enough for those you would not need podman. But it's of course still a good idea to use it. Few people know in every detail what their images are trying to do.
- hyperpape 3y agoI’m not averse to things that introduce complications for security, but it’s very poorly advertised. The overall impression a new user gets is that podman should just work as a Docker replacement, and this is frequently untrue. My own experience is that I started using podman when docker on Fedora wouldn’t work with cgroups v2. Iirc, I could (and should) have made configuration changes to make Docker work, but I wasted a lot of time tracking down issues because I thought podman would have better compatibility than it had. Upthread there’s a good suggestion that the authors should create an explicit compatibility document.
- TheDong 3y ago> podman on mac [..] the idea of daemonless-rootless is enticing Did you realize that there's a daemon on podman for mac (https://docs.podman.io/en/latest/markdown/podman-system-service.1.html https://docs.podman.io/en/latest/markdown/podman-system-serv...)? Are you aware it runs rootful podman, not rootless podman? And why do you care about those things if it's self-contained in a linux VM anyway, where there's already plenty of daemons, and plenty of root?
- jdenyc 3y agoalso check out podman desktop (podman-desktop.io) .. easy for desktop development and integration if you're on a mac or windows
- LeBit 3y agoThe doc you linked to specifically says there is no daemon on Windows and Mac. I am confused.
- TheDong 3y agoThe podman CLI tool compiled for mac doesn't allow you to run the daemon on macOS natively. The way podman desktop works includes running a podman daemon by default inside the podman linux VM. That's the daemon I'm talking about. The docker cli also runs on mac, but the docker daemon doesn't run on macOS directly, but instead as a daemon inside the linux VM. Hence, in podman desktop on macOS, just like docker desktop on macOS, you have a similar daemon running inside the linux VM that's launched. Do you understand now?
- Takennickname 3y agoPodman sucks for non-enterprise environments.
- worthless-trash 3y agoTIL: I run enterprise environments.
- xedrac 3y agoHuh? You're going to have to clarify that one. If anything, not needing a root daemon makes it much more appealing to just about every environment.
- Takennickname 3y agoTrue. But the community around docker makes it better for local use. If you really need something more, a minimal kubernetes distro is a much better option for little additional work (if any).
- op00to 3y agoI use podman orchestrated by systemd to run my home automation stuff. It took 30 seconds to set up and Just Works.
- Takennickname 3y agoPeople are mad. I should have clarified: Podman sucks in non-Enterprise environments. Either use docker or some minimal kubernetes distro. Everything else is a waste of time.
- windexh8er 3y agoThe old problem with Podman was always was that it was never exponentially better. And I don't believe, at this point, that Podman will ever replace the Docker ecosystem. And now the problem is that I view RedHat/IBM as hostile to open source, so there's no way I'm going to use or recommend it - just the same way I stopped considering using Windows platforms post Windows 2008 timeframe.
- jdenyc 3y agonot sure I understand the hostility to Red Hat, or how they might be hostile to OSS .. didn't they create podman on OSS, continue to develop and support it and give it away?
- lamontcg 3y agoYeah podman is now crippled by the association with RedHat/IBM.
- lttlrck 3y agoThis is a good reminder. I had all but forgotten RedHat/IBM.
- kobalsky 3y agojust a reminder that docker has a rootless mode that works perfectly. it does require a daemon, but it runs as the user not as root.