12 ms·
Exploring Podman: A More Secure Docker Alternative
- deleted 3y ago[deleted]
- coldblues 3y agohttps://www.techrepublic.com/article/how-to-fix-the-docker-and-ufw-security-flaw/ https://www.techrepublic.com/article/how-to-fix-the-docker-a... I almost got burned by this.
- sureglymop 3y agoDocker even just messes with iptables in its default configuration/installation. It's always been a pain point especially if one wants to use the newer nftables.
- jamesu 3y agoSpeaking of networking issues, one big problem I ran into was running out of memory for network devices when using a nested setup (requiring a system restart to fix). Would have been a great lxc alternative otherwise.
- madiele 3y agoI've got a cryptominer in one of my personal selfhosted container of a github project meant to be used with a vpn only, due to this insecure by default choice of docker. Still salty about it...
- bootsmann 3y agoGlad that podman is getting more traction tbh, too many tools are built with the assumption that people add the sudo docker group which break if you have any kind of security conscious docker setup (such as not blindly giving it root access).
- steveBK123 3y agoI always find it amusing that the cutting edge future of serverless/containers/etc was built on the back of running a bunch of stuff as root. Very cool.
- jazzyjackson 3y agoI'm trying to get up to speed with docker atm, is it the applications inside the container that are typically running as root (which people are careless about from a "whats the worst that can happen" attitude?) or is the typical pattern that people are running the docker host process as root (maybe in order to allow the host to expose ports at 80/443 without some reverse proxy/firewall in front of it?)
- zamalek 3y agoWith the default Docker installation, root in a container is root on the host. uid 1234 is uid 1234 on the host. With Podman (and Docker rootless), subuids/subgids[1] are _usually_ used. Root in the container is root only within the Linux user namespace. You can map users to real users, including yourself and root - which is how distrobox works, but it's secure by default: your subordinate users can't even access your resources. The primary limitation of rootless is networking, the kernel doesn't have a built-in way to do rootless networking in the way that you want for containers. [1]: https://www.man7.org/linux/man-pages/man5/subuid.5.html https://www.man7.org/linux/man-pages/man5/subuid.5.html
- steveBK123 3y agoYes the default is insane. Orgs that took away root from devs two decades ago let some of this stuff slip through..
- tekeous 3y agoPodman was good when it supported systemd unit files, so I could auto start and auto update containers, even entire pods with systemd. Then they removed that in favor of Quadlet. Now in order to do a single container I can do a unit file, but for a pod, I need to use a Kubernetes cluster definition. Plus, unlike Docker their containers bow to SELinux definitions, so I have repeatedly struggled with containers unable to access mapped directories. So what is it, Podman? Should I just use Kubernetes? Should I just make dedicated directories for everything instead of mapping logical places for things?
- rcarmo 3y agoThis. Quadlet wasn't really needed and just complicated matters for me, so I went back to docker-compose.
- emerongi 3y ago> Plus, unlike Docker their containers bow to SELinux definitions, so I have repeatedly struggled with containers unable to access mapped directories. Add the following to containers.conf if you don't want to deal with it: [containers] label=false If you don't like podman's default security level, there is usually a way to turn things off.
- sph 3y agoThe only times I had issues with SELinux and podman, it was because I forgot to add the z flag to the volume: podman run -v .:/app:z image This only happens locally as files in your home have strict security rules, never had any issue on a CentOS server.
- PhilippGille 3y agoNote there's also uppercase Z, for when the volume shouldn't be shared with other containers: https://unix.stackexchange.com/questions/651198/podman-volume-mounts-when-to-use-the-z-or-z-suffix https://unix.stackexchange.com/questions/651198/podman-volum...
- 3y ago
- CodeCompost 3y agodeleted
- ajb 3y agoIt's supposed to be a drop-in replacement for docker - IE, you can literally alias docker to podman. I did that for a while, but ran into some command line options that weren't supported. I see they've added some k8s integration, but not sure how you see it being a k8s alternative? Maybe a minikube alternative...
- dathinab 3y agoit's sadly only mostly a drop-in replacement it misses some features docker has and docker misses some features podman has and some subtle behaviour differences can lead unexpected outcomes (mostly in favor of podman doing things better) many of the differences are irrelevant but can be an issue in scripts calling docker/podman cli one of the more surprising discrepancies we ran into was that due to the rootless podman nature you don't need to "slowly copy the context to the daemon". In our case this lead to some slightly sub-optimal setups running just fine with podman but then taking way to long to run with docker as it copied a ton of data. generally in my experience if you only use podman or only use docker and the "drop-in" aspect only matters for switching from one to the other permanently it works grate, but if you idk. want to use docker on some systems and podman on others it might not be the best idea
- madjam002 3y agoMaybe you’re thinking of something else, because Podman is mostly a replacement for Docker and shares most of the same command line, not k8s
- dkarras 3y agoumm what gave you that idea?
- deleted 3y ago[deleted]
- politelemon 3y agoSounds good, I like their security first approach and some of the decisions they've made, going for secure defaults out of the box, and that it works with docker compose. I wonder if podman gains enough traction, at some point, they decide to go their own way with regards to the commands and the yml, because right now it seems to be a tool that 'hangs on to' docker and docker's compose file format. It would be good to have a swarm alternative in podman, it seems like k8s is a crutch for lack of orchestration. With their good security hat on they could probably come up with a sane, simple way of running containers at small scales without having to dive into a PhD in k8s which doesn't have secure defaults out of the box, while maintaining compatibility with docker compose format. Anyway that's a good intro thanks for sharing, I'll be trying it later.
- qwertox 3y agoI have such a huge arsenal of custom tools to manage Docker, that I envy Podman users because I can't move to it because of this technical debt. I just keep hoping that Docker isn't that bad and is a good alternative to Podman, because I've read mostly good things about the it, while Docker usually gets dragged through the dirt.
- pydry 3y agoPodman itself is good but on the tooling side it falls down. Docker tooling tends to work with podman but you have to do a bunch of stuff like run a server to imitate docker. At that point why bother?
- Plasmoid 3y agoOne of the nice things about podman is that it's super easy to configure image caches. So instead of rewriting all my image references to use my local cache tool, I can just set a cache directive in podman and everything works transparently.
- zaroth 3y agoCan’t you run your own docker registry and enable a pull-through cache on it with just a couple commands?
- moondev 3y agoCan you? Pull through cache is awesome but I have been leaning on harbor registry to implement it. Harbor is great but is a full featured registry application. Would be sweet if pull through can be quickly spun up ad hoc.
- deleted 3y ago[deleted]
- INTPenis 3y agoAs a certified RHEL engineer I have been using Podman for years already. To be perfectly honest I do enjoy it for all my personal container use. But at work I still use docker for our developers. There is so far nothing I can offer our developers that can match docker compose in simplicity. We even use buildah in CI pipelines when we make container images, but specifically for developer end users docker compose is still dominant.
- BossingAround 3y agoYou should be able to use podman with docker compose though (https://www.redhat.com/sysadmin/podman-docker-compose https://www.redhat.com/sysadmin/podman-docker-compose)
- geerlingguy 3y agoShould, but there are still edge cases where people use weird edge features of Docker's implementation that don't always work out of the box with Podman (it's a lot better now, though, and most of my compose files are fine either way).
- INTPenis 3y agoI've tried several times over the last few years and it always messes up somewhere, usually with networking. I stopped trying.
- BossingAround 3y agoI still don't really understand why Red Hat invests into creating a Docker alternative, but I really like it. Podman does pretty much everything Docker does, but it has more features (e.g. pods) or the way Podman does it tends to be better (e.g. daemonless container spawning process). The main issue to a common developer would be Docker compose I suppose, which if you use simple compose files, there's actually a podman-compose script that attempts to be compatible with the Docker compose spec. There's also using Podman as a backend for docker-compose [1]. Overall, in 2024, I see no reason using Docker at least on Linux boxes. Not sure how Podman fares on macOS or Windows. [1] https://www.redhat.com/sysadmin/podman-docker-compose https://www.redhat.com/sysadmin/podman-docker-compose
- koito17 3y agoI use Podman on Mac OS. I've found the experience better than Docker for the most part, especially when it comes to supporting older versions of Mac OS. The only major downside of Podman on Mac OS is that you cant use the host network in a container, but people will rarely want to use the host network in a container anyway. This is something to keep in mind if you want to experiment with network things in a container and want to retain the same hostname and IP address of your host, however. I manage to work around this limitation anyway.
- lolinder 3y ago> The only major downside of Podman on Mac OS is that you cant use the host network in a container And this isn't even a Podman-specific issue, it's true of Docker Desktop as well [0]: > The host networking driver only works on Linux hosts, and is not supported on Docker Desktop for Mac, Docker Desktop for Windows, or Docker EE for Windows Server. [0] https://docs.docker.com/network/drivers/host/ https://docs.docker.com/network/drivers/host/
- whitesnowy 3y agoI'm a podman beginner, trying to install ollama-webui(1) using Podman on M2 MBA. I started up Podman Desktop, and did a terminal command "docker run -d -p 3000:8080 --add-host=host.docker.internal:host-gateway -v ollama-webui:/app/backend/data --name ollama-webui --restart always ghcr.io/ollama-webui/ollama-webui:main" based on Github's instructions, but it gave a error message something about "host". the exact error message was ""Error": "failed to create new hosts file: unable to replace \"host-gateway\" of host entry \"host.docker.internal:host-gateway\": host containers internal IP address is empty"" Do you know what is the problem and how do I overcome this? If I run the above command using Docker Desktop, it runs and installs Ollama-WebUI just fine. Thank you. (1) https://github.com/ollama-webui/ollama-webui https://github.com/ollama-webui/ollama-webui ("Installing with Docker")
- jrm4 3y agoBig picture, it feels like Podman is essential the same way Linux used to be.* It doesn't matter if very few people use it -- it's presence prevents its much bigger privately-owned brother(s) from doing terrible things. *(I say "used to be" because Linux is now even more essential and central, not less.)
- windexh8er 3y ago> It doesn't matter if very few people use it -- it's presence prevents its much bigger privately-owned brother(s) from doing terrible things. I'm going to assume that "bigger privately-owned brother(s)" you're referring to Docker? If so, ironic given all of the evil things RedHat and IBM do in the OSS realm.
- jmnicolas 3y agoWhat evil things? (honest question) I was burned by the CentOS shenanigans but I'm not aware of anything else. And my beef with CentOS is the way they handled it, if they had left me enough time to migrate my servers we'd still be cool.
- jrm4 3y agoOh I meant Microsoft and Apple as the evil bigger brothers in the case of Linux, and Docker in the case of Podman?
- jrm4 3y agoYup -- and a fair point. It also makes me think of Facebook/Meta leaking their LLMs? But hey, I think this was actually healthy competition - supported by things that end up being "free and/or open" even if that isn't the primary intent of the spreaders or creators.
- irusensei 3y agoDon't take me wrong. Podman is great and I use it instead of docker nowadays but when I started using it thinking it was just a docker replacement I got burned by UID and GID mappings, SELINUX policies, missing DNS configuration and more. More than once I wrecked my whole setup running system migrate as a way to fix problems. It has a whole thing about security ACLs, ID mapping and labels. A chmod -R under your home folder will probably kill all your containers. While I'm happy with the results it was far from an "it just works" solution like Docker. I imagine things probably have been improved since I started using it.
- christophilus 3y agoI just started using it this year (as a way to isolate various dev environments, and as a way to prevent npm from having trivial access to my entire dev machine). It was easier to use than Docker (in my opinion). It seems to me and things have improved from what you experienced.
- freedomben 3y agoI almost never see what is IMHO the killer feature of Podman touted as a reason to prefer it over Docker: Docker mangles your network config. It is a nightmare trying to run Docker and KVM virtual machines with bridges at the same time. Podman on the other hand plays very nice OOTB. I've also had a lot of VPNs break and/or be broken by Docker. I don't know much about the way podman does networking, but whatever it is they did a good job thinking it through and it has yet to interfere with anything else I do. I definitely can't say the same for Docker
- zamalek 3y agoBuildah (which may well work with Docker, but is a Podman peer) is the killer feature in my opinion. Dockerfiles are unadulterated shite. One of my pet peeves is "bored developers" writing DSLs/programming languages (especially in YAML, but that isn't the case here) when an off-the-shelf language would have done. Dockerfiles are a genuinely fantastic example of why this nonsense needs to end. To see why, look at Buildah without `bud`. Instead of a silly DSL that becomes annoying the second your use-case veers an inch off the happy path, you can use Bash, or Fish, or whatever it is that you want. These types of bad decisions carry the into the rest of the Docker ecosystem. DCS and it's (perpetually incomplete) replacement are yet more examples: instead of using established signing protocols (like Cosign does) they had the desire to build an obnoxiously complex and hard to automate (especially key rotation) system.
- tahnyall 3y ago> It is a nightmare trying to run Docker and KVM virtual machines with bridges at the same time. I'm doing it right now, no nightmares, just works, odd.
- freedomben 3y agoAre you bridging to the main eth interface on the host? (not just a KVM private bridge). Can you share your KVM configs?
- nashashmi 3y agoPodman is free. Docker is also free, but a pain to install docker without docker desktop.
- xyst 3y agoI had some issues with podman working on my m1 mac about 1-2 yrs ago. I’ll give it a shot again. Looks like it has matured very fast.
- VoidWhisperer 3y agoI've had issues as recently as this week with podman on an m1 laptop - the container would start but after a short time would freeze completely and couldn't even be killed - only solution i found was to restart my laptop. Eventually, I gave up and went back to using docker.
- tjay1 3y agoSame, I tried it on Thursday, I would recommend people on M1 Macs to stay well clear of podman for now.
- saberworks 3y agoYep, there's a thread with hundreds of people on M1,2,3 macs having issues, it bit some people at work on newer macs. If you installed it a while ago, it's fine, but if you installed recently, it's buggered. The solution was to install podman-desktop which was somehow packaged such that it's not getting the bug (podman machine start hangs forever).
- acdha 3y agoI’ve been using it for years on M1 Macs without issue. I wrote up some notes: https://gist.github.com/acdha/9be1c3521af4f18d9f86264a889581e2 https://gist.github.com/acdha/9be1c3521af4f18d9f86264a889581...
- hirako2000 3y agoAlso worth mentioning that while docker has been catching up by offering a rootless mode for years now, it insists on running a daemon process. That daemon is a subtle but incomensurate burden when adopting the least privilege principle. In environments running multiple hosts which themselves run multiple containers, typically: k8s, it forces your hand in either giving in and grant docker (the daemon) root privilege if any one of your container needs root, or to exclude that container from running in that environment altogether (since it would fail to execute if the docker daemon is in rootless mode). Of course the most secure and wise option would be to refractor that container and whatever it's doing to run rootlesssly, but sometimes this is simply not a reasonable or even possible option in order migrate massive complex platform of hundreds of micro services with its own history and justified security exceptions. K8s (and Openshift, which adopts a stronger security by default configuration set) provides control over which service accounts is granted such exception. tl-dr: use podman/buildah rather than docker, use openshift rather than vanilla k8s.
- throwawaaarrgh 3y agoSomebody should tell them Docker can run in rootless mode.
- dathinab 3y agoIt can but: - They by default don't. - It's only semi officially supported. It requires non official tooling, through they link to that tooling officially in their doc. But issues specific to rootless docker seem to not be much of a priority. - roots less docker sometimes has some slight issues, but mostly minor stuff The fact that they can make it save to use, but do not, is a really huge red flag. And it's not the first time they didn't take security on linux not serious at all. To clarify what I mean with "make it save", the docker user group allows easy gaining root light access, which is a huge security no-go. And the alternative is using sudo or similar all the time which also is a security no-go (if you e.g. have a dev system, it's okay for starting docker images as services, but then limitations with systemd integration make podman often a better choice here anyway). And while there are ways to make it work without a security no-go and the daemon the last time I checked they weren't out-of the box and in my opinion too brittle. Now if you have a single user system you maintain yourself and have a single user+admin+sudo right user or similar maybe then you don't care about docker group or using sudo too often. But if it's a company managed system with reasonable security requirements it's an absolute no go.
- AkihiroSuda 3y ago> It requires non official tooling Rootless Docker has been merged into the official since Docker 19.03, and graduated from experimental since Docker 20.10. The "tooling" is available in the official apt/dnf repo too: - https://download.docker.com/linux/ubuntu/dists/jammy/pool/stable/amd64/docker-ce-rootless-extras_24.0.7-1~ubuntu.22.04~jammy_amd64.deb https://download.docker.com/linux/ubuntu/dists/jammy/pool/st... - https://download.docker.com/linux/centos/9/x86_64/stable/Packages/docker-ce-rootless-extras-24.0.7-1.el9.x86_64.rpm https://download.docker.com/linux/centos/9/x86_64/stable/Pac...
- tdiff 3y agoCould anyone please advise a paper on Docker architecture, discussing its design choices (e.g. client-server model) in detail?
- tdiff 3y agoOne other thing podman (unlike Docker) is missing is ability to run x86 images of Apple silicon under Rosetta. QEMU turns out to be too slow for real use.
- oasisaimlessly 3y agoCan anyone tell me why neither Docker nor Podman allow you to dynamically modify forwarded ports? It would allow zero-downtime updates of containers (starting new container, wait for it to be healthy, update port forwards, stop old container). And no, reverse proxies do not solve this problem; lots of protocols (e.g. SSH) have no equivalent to X-Forwarded-For for identifying the remote host.
- bostik 3y agoLikely due to technical limitations. At least docker does its port-forwarding with iptables (or these days, nftables), and the forwarding rules themselves span multiple custom tables/chains. If you ever do 'iptables-save' to inspect what rules have been created when a container is running, it may look a bit funky. So updating a purportedly single rule might actually require to update several underlying traffic mangling rules, with logic that is not readily apparent. Or even easy to reason about. When you add the ability to route traffic directly from container to container without passing through the outermost interface, things can get quite hairy.
- tahnyall 3y ago[dead]
- coppsilgold 3y agoI tend to just make and run shell scripts that configure and run bubblewrap[1]. Everything is nicely explicit and allows for a good mental model of what's going to happen when you run it. source "/path/bwrap_helper.sh" FLAGS=( ${FLAGS_ROOTFS_DISTROX_MIN[@]} ${FLAGS_ENV_XDG_GUI[@]} ${FLAGS_PULSE[@]} ${FLAGS_GPU_ACCEL[@]} --new-session --bind /path/jail123 /home/user ) exec bwrap "${FLAGS[@]}" --seccomp 10 10< /path/a_filter.bpf -- /usr/bin/gui_app "$@" [1] <https://github.com/containers/bubblewrap https://github.com/containers/bubblewrap>
- Helmut10001 3y agoI agree that rootless containers and isolated namespaces are critical security features. But with docker rootless, this is also possible and not complicated. You just have to do it. I have written a blog post to set up Mastodon in docker rootless with all the best practices currently available [1]. The benefit with sticking with docker is that accessibility is better: More communities, more blogs, broad availability of docker compose configs, more peers knowing how to use it etc. In the end, both podman and docker run processes in isolated namespaces on the host. [1]: https://du.nkel.dev/blog/2023-12-12_mastodon-docker-rootless/ https://du.nkel.dev/blog/2023-12-12_mastodon-docker-rootless...
- WhyNotHugo 3y agoThe comparison is unfair in that it compares docker-as-root vs rootless podman. A more sensible comparison would be between docker rootless and podman rootless.
- AkihiroSuda 3y ago> Podman is designed to help with this by providing stronger default security settings compared to Docker. Features like rootless containers, user namespaces, and seccomp profiles, while available in Docker, aren't enabled by default and often require extra setup. Seccomp has been enabled by default since 2015: https://github.com/moby/moby/pull/18780 https://github.com/moby/moby/pull/18780 It is true that Rootless isn't enabled by default but its "extra setup" can be done with a single command (`dockerd-rootless-setuptool.sh install`)
- snapplebobapple 3y agoCan't do nfs mounts rootless, so I don't really see the point since my whole infrastructure is using nfs mounts and docker already.