5 ms·
> and does not suffer from many of the docker shortcomings. Would you care to elaborate on the shortcomings? I use Docker in my home lab and have taken a coupl
by HankB99 2y ago
> and does not suffer from many of the docker shortcomings.
Would you care to elaborate on the shortcomings? I use Docker in my home lab and have taken a couple runs at Podman but have not been highly motivated and reverted to Docker rather than fiddle with things to get my containers working. If I were aware of significant benefits for my usage, I might be inclined to keep trying. If the benefits are more relevant to enterprise or cloud environs, it probably does not matter much to me.
My use cases include Gitea (git server) which opens privileged ports inside the container that get mapped to unprivileged ports on the host and I believe that was a problem area.
Thanks!
- worksonmine 2y ago> opens privileged ports inside the container that get mapped to unprivileged ports on the host You can either allow those ports to be mapped on your host, or you can map a higher port on the host 8000:80 or 4443:443. I did the former. The biggest problem I have with docker other than root is that it touches the firewall for convenience. Any port you map on the host will be opened in nftables, as per the documentation[1]. Very dangerous default that few developers realize is a problem. You probably only want 80/443 open and proxy your subdomains on the host, but all ports are now exposed to the internet. [1]: https://docs.docker.com/network/#published-ports https://docs.docker.com/network/#published-ports
- HankB99 2y ago> Any port you map on the host will be opened in nftables ... That rates a "Wow!" but seems like something more important to Enterprise/Cloud. It seems like it would be a Bad Thing to open a port because a DB server ran in a different container. That's not something that should be opened unless the DB is on a different host (VM) from an application that uses the DB. In my case I have a firewall/router protecting my home LAN and don't generally run firewalls on individual hosts.
- worksonmine 2y agoAny website you visit on your home network could do a portscan on the local network and figure out what you're hosting. Hackers are creative. Chrome has some mitigations against this but unfortunately not Firefox last time I checked. Do you have any IoT devices? Smart TV? It's always a good idea to lock down everything you can and avoid unsafe defaults. If podman causes any friction there's most likely a good reason behind it. For me there are none and I've lost count of the containers I'm running.