16 ms·
Quadlets might make me finally stop using docker-compose
- Already__Taken 3y agonice to see more podman/systemd ties but --user I find even harder to let tabs on what containers are running, especially as you check on other users, remembering the socket mount is quite unpleasant. I'm really a fan of tilt and just using k8s yaml I'll probably need to deploy anyway. but I don't see why you couldn't make that reconciliation loop drive podman instead. but then docker bought tilt so...
- xgbi 3y agoSay what you want about docker compose, but when I see the amount of scaffolding necessary for this, with so many catch words like butane or ignition, I’m happy with my good ol’ docker composé file where everything is neatly organized. In one glance I can see what is deployed, depends on what and what net / volume is used. For simple projects, it’s hard to beat
- overbytecode 3y agoButane/ignition is the configuration to set up CoreOS (similar to configuration.nix in NixOS) it has nothing to do with Quadlets.
- deleted 3y ago[deleted]
- hansihe 3y agoI was confused by this article in the beginning, it does a pretty bad job at drawing a distinction between the pure quadlet example at the start and the example of using CoreOS to build and launch a VM that starts containers. The basic usage of podman quadlets is putting an `app.container` in `/etc/containers/systemd/` containing something like the first snippet and then starting the unit. For someone familiar with systemd, this seems very very nice to work with.
- imiric 3y agoI'm still not clear whether quadlets are a feature of Podman or systemd... The reliance on systemd is an issue on its own. Much has been said about its intrusion in all aspects of Linux, and I still prefer using distros without it. How can I use this on, say, Void Linux? Standalone Podman does work there, but I'm not familiar if there were some hacks needed to make it work with runit, and if more would be needed for this quadlet feature.
- gigatexal 3y agoI mean the best part about open source and Linux is that you have choice. Do you want to run an OS devoid of SystemD? Fine. Will you be going against the tide and leaving a large part of the ecosystem behind? Yup. I’ve chosen to embrace systemd and learn it as it is the defacto standard it seems rather than fight what I think is a futile war against it. That being said. I won’t force you to use it if you don’t. But I do not see quadlets using systemd as a failing.
- hexo 3y agosystemd is extremely intrusive. anything dependent on it is a failure.
- memefrog 3y ago[dead]
- voidnap 3y agoThis is such a bizarre comment. I run systemd a number of Linux machines currently but does that mean they are failing? Is taking advantage of systemd's features a failure? They run and do their function so in what sense are they failing or what does failure mean?
- figmert 3y agoBy my calculations, considering much of the world runs on RH/Ubuntu/Debian, all of which use systemd, things depending on systemd are far from being a failure, cos they'll run on the majority of systems.
- worksonmine 3y agoI also miss the simplicity of compose, but for me running rootless is worth the tradeoff. It also forced me to rethink how I used containers and I realized many times a simple podman_run.sh is enough. It also helped me understand containers better because there was less magic going on, sometimes limitations can be good.
- rewmie 3y ago> I also miss the simplicity of compose, but for me running rootless is worth the tradeoff. To setup/tear down software dev environments deployed locally, the root/rootless discussion isn't really relevant. Ease of deployment and ease of use are critical though, and Docker is above all a development experience victory.
- worksonmine 3y agoRelevant to who? The damage done with container escape is bigger on my machine than any production server I have access to. And there are a lot more packages running in my dev environment than on production servers. When it comes to security or convenience I always choose the first but I know most people wont. Podman-compose isn't as good as docker but it exists, and you can run docker-compose with podman as the runtime. I don't need it as my environments are simple and even wrapping the commands in shell scripts would be overkill. But the option is there.
- yrro 3y ago> The damage done with container escape is bigger on my machine than any production server I have access to. It's worth pointing out that if you're running on Fedora/RHEL then containers are confined to the container_t domain, with a unit per-container MCS label. SELinux policy will prevent a process that has broken out of its namespaces from being able to read/write files from the host or from other containers, or being able to kill or read the memory of or (I'm assuming, haven't checked) ptrace processes from the host or other containers.
- rewmie 3y ago
- fbdab103 3y agoIt is not entirely obvious - can I use quadlets in an ad-hoc fashion to spin up a project? The example makes it seem like it is exclusively for long running services.
- deleted 3y ago[deleted]
- TheFragenTaken 3y agoYes! Can we talk about projects consistently deciding to invent new nomenclature for their entities or products. Is it an effort to lock you in to their system? Just call things what they are.
- jauntywundrkind 3y agoOverall this looks really good but it also obfuscates whether how & where this really integrates with systemd. Maybe everything is this easy & good. Maybe this is an /etc/systems/system/WordPress.quadlet file, part & parcel to everything else in the systemd-verse. But it doesn't say clearly whether it is or isn't. It's an acontextual example. I think it's powerful tech either way, but so much of the explanation is missing here. It focuses on the strengths, on what is consistent, but isn't discussing the overall picture of how things slot together. In many ways I think this is the most interesting frontier for systemd. It's supposedly not a monolith, supposedly modular, it so far that has largely meant that components are modular, optional. You don't need to run the pretty fine systemd-resolvd, for example. But what k8s has done is make handling resources modular, and that feels like the broad idea here. But it seems dubious that systemd really has that extensibility builtin; it seems likely that podman quadlet is a secondary entirely unrelated controller, ape-ing what systemd does without integrating at all. It seems likely that's not a podman-quadlet fault: it's likely a broad systemd inflexibility. Could be wrong here. But the article seems to offer no support that there is any integration, no support that this systemd-alike integrates or extends at all. Quadlet seem to be a parallel and similar-looking tech, with deep parallel, but those parallels from what I read here are handcrafted. Jt's not quadlet that fails here to be great, ut systemd not offering actual deep integration options.
- goku12 3y agoQuadlet uses SystemD Generators [1] feature. Generators are a way to convert non-systemd-native configuration extensions (like containers, volumes and networks in case of quadlets) into regular systemd-native configuration like service unit-files. The quadlet generator converts the podman extension for systemd into regular service file that you can examine yourself. Non-root podman container services are in /run/user/<uid>/systemd/generator. Here is a blog post that describes the design in detail (slightly dated): [2] [1] https://www.freedesktop.org/software/systemd/man/systemd.generator.html https://www.freedesktop.org/software/systemd/man/systemd.gen... [2] https://blogs.gnome.org/alexl/2021/10/12/quadlet-an-easier-way-to-run-system-containers/ https://blogs.gnome.org/alexl/2021/10/12/quadlet-an-easier-w...
- yrro 3y ago
- malmz 3y agoI have been having a blast using quadlets on my tiny home server. Feels like I'm learning how to use systemd which is a nice bonus. My workflow consists of just connecting vscode over ssh and editing files as needed, which works well since everything is owned by my user.
- frej 3y agoNitpick you wonder why yaml is preferred to ini files when it is lined up to each other.
- rewmie 3y agoINI files are not specified anywhere, so it ends up being a implementation-defined free-for-all. Also, YAML supports data structures that INI files don't. I don't understand the hate that YAML gets. If you're not tasked with writing a parser, the data format just works as expected.
- MoreQARespect 3y agoIt's not type safe.
- rewmie 3y ago> It's not type safe. I fail to see what leads you to believe this is a relevant point when discussing INI files as the alternative to YAML.
- awestroke 3y agoYaml coerces values (the string "on" is coerced to bool true for example), with ini you do any conversion from strings yourself
- rewmie 3y ago> with ini you do any conversion from strings yourself INI isn't specified, thus you cannot claim that the INI format does something a certain way. The best shot at a specified INI file format might be TOML, and even that format is subjected to the same type of criticism.
- deleted 3y ago[deleted]
- 3y ago
- politelemon 3y ago> However, as with watchtower, that’s another external dependency. Docker compose is part of docker now, it's just another subcommand.
- deleted 3y ago[deleted]
- goku12 3y agoWhile you're technically correct, docker compose uses yet another process supervisor (the docker daemon) while systemd is already capable of doing that. This is probably what the author meant by 'external dependency' - not the need to install compose separately. Quadlet delegates the supervision to systemd daemon, eliminating this duplication of supervisor functionality. Kubelets in K8s also have similar duplication of supervisor functionality. Perhaps this is a good place to mention the Aurae runtime [1], which is designed to replace systemd, docker daemon, kubelet, etc on dedicated worker nodes. Sadly, its chief designer Kris Nova passed away recently in an accident. I wish the rest of the team the strength of carry her legacy forward. [1] https://aurae.io/ https://aurae.io/
- pcthrowaway 3y agoIt unfortunately looks like Aurae is unmaintained at the moment.
- r4indeer 3y agoNot quite, docker-compose is shipped separately by Docker as docker-compose-plugin. The plugin can then be reached with the subcommand "docker compose". However, I agree with your sentiment. It's basically a part of any modern Docker installation now. Calling it an external dependency "like watchtower" is not a fair comparison.
- shuiling 3y ago[dead]
- ThinkBeat 3y agoWhy the name quadlets? Classical definition: > A word consisting of four bytes Quad implies 4 something or rather. What does it refer to here? 4 sections of configuration?
- timenova 3y agoMaybe they mean Quadrant.
- twic 3y ago> The original Quadlet repository describes Quadlet this way: > What do you get if you squash a Kubernetes kubelet? > A quadlet So it's based on reinterpreting the root "kuber-" which ultimately means something"to do with "turn", as "cube", and then metaphorically reducing a cube to a square.
- dizhn 3y agoI thought it was half a K8s.
- goku12 3y agoThey squashed kubelet, not K8s. By that, they probably mean that they got rid of the kubelet and delegated its functionality to systemd (which is already there besides the kubelet if the node uses systemd based distro). Note that quadlet is also capable of creating services based on K8s manifest.
- dizhn 3y agoYour explanation makes sense. Thanks.
- goku12 3y agoAn article [1] from Redhat has this excerpt: > The original Quadlet repository describes Quadlet this way: >> What do you get if you squash a Kubernetes kubelet? A quadlet [1] https://www.redhat.com/sysadmin/quadlet-podman https://www.redhat.com/sysadmin/quadlet-podman
- Uptrenda 3y ago[flagged]
- worksonmine 3y agoWhat? If you use containers this simplifies the stack rather than complicating it. Instead of kubernetes and other popular tools it's just rootless podman and systemd which is already there. I'm using a similar setup and this excites me. It's too new to be in my repository but as soon as I get an extra hour I'll compile it and take it for a spin.
- silisili 3y agoIf you want to really simplify using containers, you could just use systemd-nspawn.
- worksonmine 3y agoDepends what you mean by simplifying. Does it have registries and the ecosystem of OCI containers? The killer feature of podman for me is that it works with docker which like or not most people are using. But I'll look into nspawn could be useful.
- silisili 3y ago> Does it have registries and the ecosystem of OCI containers Not at all. If you want all that, docker/podman is better. But if ultimate simplicity is your goal, it's worth looking into. They are -very- lightweight and fast by comparison.
- deleted 3y ago[deleted]
- gigatexal 3y agoYeah … this response is devoid of substance. What’s all this nonsense about “soy”? Why not critique the approach with what is better about your approach or docker-compose or whatever it is you use and talk about the merits.
- asabil 3y agoIt's quite unfortunate that this article mixes up what's necessary for podman quadlets with coreOS concepts. With quadlets, the only thing required is to drop a `.container` file in the right place and you end up with a container properly supervised by `systemd`. And this of course also supports per-user rootless containers as described in [1]. [1]: https://www.redhat.com/sysadmin/quadlet-podman https://www.redhat.com/sysadmin/quadlet-podman
- nisa 3y ago> With quadlets, the only thing required is to drop a `.container` file in the right place and you end up with a container properly supervised by `systemd`. Is it? He defines a .network file in that butane config without it won't work. Not really obvious. I'm sure this has a use-case and it's nice to have but personally I'm not convinced. You can switch on user-namespaces in docker-daemon or even run docker itself rootless - I guess if you are in Redhat land and use podman anyway it's an alternative but for instance where is this thing logging into? journalctl --user? Can I use a logshipper like loki with this? Is there something like docker compose config that shows the fully rendered configuration? I personally don't see the point and it feels like overly complicated.
- twic 3y agoIt will log to wherever you configure. By default, the journal. And [0]: > Currently, Promtail can tail logs from two sources: local log files and the systemd journal (on AMD64 machines only). Whether it supports user services, I don't know. [0] https://grafana.com/docs/loki/latest/send-data/promtail/ https://grafana.com/docs/loki/latest/send-data/promtail/
- INTPenis 3y ago.network is only required if you need a network, just like you define networks in docker compose for some containers to have one shared private network.
- nisa 3y agoyeah spend some time on the docs for this and it's pretty straight forward - the article and the repo kind of omits this but it's also for a different usecase. Was just irritated when I wrote that comment. It's really some oci container to systemd shim system that uses podman.
- TekMol 3y agoTo me, this big problem with Docker is that it does a ton of changes to my system, even when I don't use it. It runs a daemon, it uses a bunch of IPs, it mounts a ton of stuff ... Is there a reason for all that noise and complexity? There can't be a reason until I run a container, right? And even then, it seems way too much. Is it different when using Quadlets?
- jeppester 3y agoOne of podman's selling points is that it doesn't need a daemon, and it runs without root privileges. I'm not familiar enough with the lower level details to know how it works, but it certainly feels less like you are making "a ton of changes to the system" compared to docker
- viraptor 3y agoThis. Run podman without a daemon and with host networking and the only "weird" configuration you'll see is the overlay fs. Everything else is quite often an unnecessary overhead.
- soupdiver 3y agoThis is about Podman, not Docker
- v3ss0n 3y agoWhat worse is , it screws up the firewall rules. Podman avoid that so , quadlets should be fine? Podman supposed to be drop-in replacement for docker but - last try (4 months ago) of podman to run our development docker containers fails to build so i think Podman is still far away from docker replacement.
- jve 3y agoYeah, I also tried ~months ago. To be fair, I'v only tested out dev containers with docker, so I'm too weak to debug things what went wrong. Any article out there on how to have windows + wsl2 + podman + vscode devcontainers working?
- darkwater 3y ago> My container deployments are often done at instance boot time and I don’t make too many changes afterwards. I found myself using docker-compose for the initial deployment and then I didn’t really use it again. I used a very similar approach in the (now EOL'ed, gonna be replaced by full K8s) infra at $DAYJOB. My main reason to stick with docker-compose is because developers are familiar with it and can then easily patch/modify the thing themselves. Replacing with something systemd will add a dependency over the people that know systemd (which are not usually application developers in your average HTTP API shop)
- GTP 3y agoI would add that this is the use case of a server running some services. But during development you may want to restart and/or rebuild a container multiple times, maybe this is still better done with docker-compose.
- INTPenis 3y agoI started using quadlets for new system designs a month ago and I feel like I'm neck deep in it now. My conclusion is that there is absolutely no reason to stop using docker-compose if your developers are comfortable running one command, on one file, in one git root. Quadlets are basically docker compose, in systemd. They've finally done it, systemd has it all and now it even has docker compose. ;) That's really all it is in practice. I'm going to continue using it because I'm a RHEL kinda guy, but don't make it up to be magic.
- cyberax 3y agoThe next step: systemkubed.
- runiq 3y agoNah, we got that already. Quadlet can handle k8s manifests. https://man.archlinux.org/man/quadlet.5.en#Kube_units_%5BKube%5D https://man.archlinux.org/man/quadlet.5.en#Kube_units_%5BKub...
- INTPenis 3y agoYes but when is someone going to add logic on top of this to make it a full blown distributed container orchestrator? Could it be done with systemd and dbus? Can dbus be distributed among several systems like mmc on Windows? I have no idea, just some questions that popped into my head lately.
- alexlarsson 3y agohttps://github.com/containers/bluechi https://github.com/containers/bluechi
- INTPenis 3y agoFett!
- 3y ago
- omneity 3y agoThis is pretty cool and might replace my use of nomad on my home server.
- contravariant 3y ago> you’ll see a WantedBy line. This is a great place to set up container dependencies. In this example, the container that runs caddy (a web server) can’t start until Wordpress is up and running. Either this must be some systemd weirdness that I thankfully haven't had to deal with until now, or I'm misunderstanding something. Did I understand correctly you don't specify which services you need but rather which ones depend on your service? So if your service doesn't start you'll need to check the configuration files of all other services to figure out which dependency is preventing it from starting?
- fireflash38 3y agoYou can do it the other way if you want, using After= or Requires.
- toyg 3y agoi don't think that's the case for .container files, according to https://docs.podman.io/en/latest/markdown/podman-systemd.unit.5.html#enabling-unit-files https://docs.podman.io/en/latest/markdown/podman-systemd.uni...
- alexlarsson 3y agoThat section is only for the enablement of units, and is equivalent to the install section in a service file: https://www.freedesktop.org/software/systemd/man/systemd.unit.html#%5BInstall%5D%20Section%20Options https://www.freedesktop.org/software/systemd/man/systemd.uni... You can still use all sorts of dependencies in the [Unit] section: https://www.freedesktop.org/software/systemd/man/systemd.unit.html#%5BUnit%5D%20Section%20Options https://www.freedesktop.org/software/systemd/man/systemd.uni...
- mangecoeur 3y agoYou can define Before, After, or WantedBy to define the dependency order. Systemd them makes sure to start services in the right order, it starts them by default but you can also configure services not to start if nothing depends on them.
- arisudesu 3y agoThe syntax and examples in the article assumes usage of SystemD as service manager. Does it work on distros without SystemD too? Docker-compose does. I also do not understand separation of services to different files. Is it supposed to be more convenient? With docker-compose, the whole application stack is described in one file, before your eyes, within single yaml hierarchy. With quadlets, it's not. Lastly, I do not understand the author's emphasize on AutoUpdate option. Is software supposed to update without administrator supervision? I guess not. What are the rules for new version matching: update to semver minor, patch version, does it skip release candidates etc?
- dathinab 3y ago> Is software supposed to update without administrator supervision yes proper CI is a thing, and containers not being updated is actually quite a bit of an issue in the current software industry especially if combined with custom registries auto update is quite a neet thing oh also it's a SystemD feature to let SystemD manage your containers so why are you asking if it works without SystemD?
- patrec 3y agoUpdating your custom registry with new upstream dep versions after testing in CI with the all services you care about is fine. But the OP seems to just blindly pull the newest wordpress images from upstream or am I missing something? How is this meant to work reliably? I guess given wordpress's security record taking breaking your site from time to time is preferable to your site being broken into from time to time.
- athrowaway3z 3y agoWhat are you talking about? > Running containerized workloads in systemd is a simple yet powerful means for reliable and rock-solid deployments. They say its reliable and rock-solid. Isn't that enough for you? /s --- Honestly, the amount of companies who: Don't understand the problems, forgot history, and think we're innovating into new territory because of hyped up branding is utterly baffling in the whole container space. I'm not saying they're all bad, and better common tools are a good thing. But i see so many companies operating at [required complexity level] + 1 in the hopes to no longer be bothered by simpler problems.
- parhamn 3y agoIt seems like the coolest part of this isn't the systemd part necessarily (unless you're a systemd fan). It's that the combination of Quadlets + coreos gives: - Node starts up with a container daemonized - Automated updates of the registry image - A nice single arg to pass to your cloud provider CLI userdata that launches the OS + container (vultr-cli in this case) I guess you can do something similar with any linux userdata but the script wont be as clean. Has anyone built something lite to launch docker containers on boot in ubuntu (this is particularly helpful for cloud provider CLIs) without writing the whole script manually? Something nicer than `apt update && apt install -y docker && docker run --rm --restart-always ...` that includes the registry autoupdate.
- punkbit 3y agoSeems interesting, but looks quite verbose with those ignites butanes etc. Started with SystemD then just got lost in noise.
- viraptor 3y agoWhile quadlets are cool, this just makes me miss the rkt runtime. https://github.com/rkt/rkt https://github.com/rkt/rkt It integrated with systemd properly quite a while ago.
- crabbone 3y agoI never understood the appeal of docker-compose (you can accomplish roughly the same thing by having a Shell script that calls docker client, but skipping the Python clown fiesta with dependencies, environments etc.) Quadlets seems not exactly a replacement for the function docker-compose was supposed to perform though, or am I wrong? It seems like its target audience is administrators who are supposed to run containers as systemd services (questionable choice, but probably there are people who want that)... What am I missing?
- shortrounddev2 3y agoShell scripts suck to write and bash/zsh is a terrible language to have to deal with
- deleted 3y ago[deleted]
- crabbone 3y agoAnd so does Python. But Python is unnecessary for this task. So, having to choose between two evils, I'd choose the necessary one.
- shortrounddev2 3y agoIdk what python you're talking about with docker compose
- NoNoisle 3y agoFor real. Maybe he should try docker compose v2
- crabbone 3y agoWhy? What do I stand to gain from using this? Marginal speed improvement in some cases and a lot of headache trying to debug it in other cases? docker-compose offers an alternative. It doesn't offer any genuinely new functionality. It may work for you if you don't know how to use the other alternative, or the other alternative is inconvenient for you for some other reason, but if it's not, it's just an extra tool that you don't need.
- dboreham 3y agoFeel like I've fallen out the back of the wardrobe into Narnia: the way we want to run containers on a machine is part of systemd? A thing that nobody understands, that isn't present on most machines.
- aerzen 3y agoIt's not present on most machines? All Linux boxes I've seen used systemd. It's the most used init system. If you want to say that there are machines that don't have systemd which therefore cannot use quadlets, that's like arguing that something made for Linux is useless because "Linux is not present on most machines".
- whalesalad 3y agosystemd is everywhere and has been for a long time.
- madspindel 3y agoActually, I believe "podman generate kube" is even better: https://www.redhat.com/sysadmin/kubernetes-workloads-podman-systemd https://www.redhat.com/sysadmin/kubernetes-workloads-podman-... You can run your docker-compose file, then run "podman generate kube" and you will get a Kubernates yaml file. Then you can run: $ escaped=$(system-escape ~/guestbook.yaml) $ systemctl --user start podman-kube@$escaped.service And you can enable it to start on boot. It will read the yaml file and create the pod.
- yrro 3y agoFYI you'll have to enable lingering for your user on that system. Otherwise your user services won't start on _boot_ but only when you log in.
- moondev 3y agoOr you just run the kubelet(with systemd) and drop your manifests I to /etc/kubernetes/manifests Nothing can kube better than the kubelet! The new sidecar support for init containers can be used today. Every other abstraction is playing catch up
- sunshine-o 3y agoQuadlets are very much a welcomed integration but last time I tried to create an users Quadlet in .config/containers/systemd/ with a linuxserver.io image I ended up with all sort of files owned by strange UID & GID. So I had to add --userns keep-id to my container unit what caused all sort of problem because of podman apparently. So you always end up with the kind of investigation & fiddling that shouldn't be necessary after 10 years of docker & containers.
- broknbottle 3y agoI believe this is due to the linuxserver.io images actually being customized specifically for usage with docker. For images intended for rootless deployments e.g. podman, take a look at the onedr0p container images, https://github.com/onedr0p/containers https://github.com/onedr0p/containers
- sunshine-o 3y agoThank it looks great ! and yes, I believe it is the policy of linuxserver.io not to test or support officially podman. I have been trusting the plan but I notice that after 10 years of container industry standard etc. we have to search for podman friendly images to enjoy integration with the common Linux service manager... Now if container-based Linux distributions are the future I'm starting to wonder if we are not gonna soon see RedHat & co. packaging docker images in RPMs to make sure guarantee things work together & people don't badly mess up the security...
- stryan 3y agoFun fact, OpenSUSE actually already does that for some common server software (LDAP, dovecot, etc); they're quadlet/systemd unit files packaged up as RPMs though, I don't think they actually include the container image.
- sunshine-o 3y agoGarch, they already put the container in a package. We've gone full circle...
- gonzo41 3y agoMaybe I'm not seeing something here. You have docker compose run by systemd and your compose file has restart always in it. What problem is getting solved by quadlets, or is it just a ergonomics thing?
- stallmanwasrigh 3y agoBeen waiting a long time for this. Container orchestration always seemed like a natural progression as systemd already manages cgroups for other services. Unified plain text format.
- fariszr 3y agoI don't see how this is anything like compose. With quadlets you have to create a file for each container and deal with creating volumes and so on. Whereas with Docker it's one file, one command and you're done, you don't have to deal with anything else.
- whalesalad 3y agoFor anything other than a hello world type project a compose file will fall over kinda quick. I would much prefer to (ahem) compose smaller things together and systemd is great for that.
- deleted 3y ago[deleted]
- rastapasta42 3y agoLolol have been running compose in dev & prod for 7 years - still the best tool around.
- whalesalad 3y agoIt will depend on the complexity of the stack, the number of environments you are deploying into, the number of devs on the team etc. It can work, and if it is working for you in this manner don't change what isn't broken, but in my experience for sophisticated systems with many services, envs, and developers it becomes unmanageable pretty quickly.
- GabeIsko 3y agoThat might work for whatever you are doing, but the truth is that root-ful containers are not appropriate for a lot of applications, and docker as a layer to your container runtime is rough sometimes. I don't think docker wants to continue to develop this anyway - they have had enough problems trying to be profitable so instead it is time to focus on docker desktop and charging for docker hub image hosting. I feel like we are kind of in this weird limbo where I know I need to move to a podman focused stack, but the tooling just isn't there yet. I guess that is what makes Quadlets interesting, but idk if a single tool will really emerge. There is also podman-compose floating around. I still feel like I should hold of on some stuff until a winner emerges. So at home I'm still on docker with compose files. Although I will be moving to kubernetes for... reasons.
- timost 3y agoA trick I have used sucessfully is to use docker-compose with podman as the engine. The way I do it is by starting podman's systemd service which exposes a docker compatible API over a Unix socket. Then export DOCKER_HOST pointing to the socket and you can run docker-compose with podman transparently.
- zb3 3y agoI'm happy with docker-compose, but it seems RedHat really doesn't want me to use such simple and easy to use thing that is not as tightly coupled with other RH-specific parts as the replacement they promote. But this only makes me like docker even more :)
- gloryless 3y agoI don't understand how people go through the effort of writing an article about containers but start out with a basic incorrect statement. They don't disconnect from the OS, and in fact are dependent on the OS.