6 ms·
I prefer quadlet for 2 reasons: 1. Podman is simpler than Docker. There is no long-running daemon. Rootless is default. 2. Quadlets can be managed as systemd
by dharmab 1y ago
I prefer quadlet for 2 reasons:
1. Podman is simpler than Docker. There is no long-running daemon. Rootless is default.
2. Quadlets can be managed as systemd services, giving me the same tools to manage and view logs for system daemons and containers.
Quadlets have been especially nice for bundling up an AI app I wrote as a cloud-init file, making it easy to deploy the hardware, software and models as one artifact.
- pydry 1y agoquadlets == systemd which requires root to run. this is NOT the same thing as "systemd cant run non root containers". OBVIOUSLY it can, just as docker can run non root containers. Making systemd a necessary dependency to run > 1 container kinda negates many of the the nice advantages that podman has of not requiring root. podman compose doesnt require root and would serve as a substitute but it's a very neglected piece of software.
- zacwest 1y agoYou can do non-root systemd units, including Quadlets. See <https://docs.podman.io/en/latest/markdown/podman-systemd.unit.5.html https://docs.podman.io/en/latest/markdown/podman-systemd.uni...> under "Podman rootless unit search path."
- pydry 1y agoyou can run docker containers without them requiring root too. systemd itself is a root service. it shouldnt be a necessary dependency to run > 1 containers without root. somehow it is.
- znhll 1y agoI recently started making the switch from docker (and docker compose) to using podman and quadlet, but holy crap is the documentation for podman quadlets a big f-you wall-of-text mandoc that would make Torvalds proud. I've read thru that and am still not quite sure of how to get from point A to point B. To replace a single docker compose file, sounds like one needs to manually create a number of .container, .volume, .network, .kube files correctly so systemd can spin up a container pod? Is that what I'm reading? Is there nothing that can generate that from a docker-compose.yml?
- zacwest 1y agoI've used Podlet <https://github.com/containers/podlet https://github.com/containers/podlet> somewhat successfully for this.
- worewood 1y agoI agree. That documentation really needs some love. But if you see the discussions on github issues about quadlet features a common theme is maintainers dismissing requests because "that shouldn't be done in production" or "that won't scale". It seems they can't wrap their head around people wanting to do simple things or someone doing things by themselves at home and not for work at a big company or corporation, and that reflects on that documentation. Working for one myself, which does have a support contract wit Red Hat, I kinda get where they're coming from--if they make it easy to shoot yourself in the foot, dumb people shoot themselves in the foot in production and they have to fix the mess later. But for that they could have a sanctioned build for clients and a community build for everybody else, just like they have Fedora and RHEL.
- voxadam 1y agosystemd user units can be run by non-root users. https://wiki.archlinux.org/title/Systemd/User https://wiki.archlinux.org/title/Systemd/User
- pydry 1y agonot the point as i mentioned above. systemd itself requires root.
- voxadam 1y agoInstalling packages (like podman or moby/docker) using dnf and apt requires root as well, so I'm not sure what your point is.
- pydry 1y agomaking systemd - a root service - a necessary dependency in order to orchestrate > 1 nonroot containers is both unnecessary and bad architecture. It was a shitty decision that renders it just "a less popular docker" and not "a better docker".
- linuxandrew 1y agoPodman doesn't have a dependency on systemd. e.g. it is packaged in Void Linux. Podman has a better architecture than Docker in that it can easily run on a non-privileged user. Quadlet (aka podman-systemd.unit) is a podman-systemd integration which can make it easy to launch and orchestrate podman containers via systemd. You can get all if the systemd dependency handling, require other units to run after a container finishes, and all sorts of other useful things. Systemd "user" units (systemctl --user) also works here with the containers running as a non-privileged user in a non-root systemd context. Just to be clear, Quadlet is just an integration and you can still run podman without it. You can still run podman on non-systemd systems as well.
- dharmab 1y ago
- exceptione 1y agosystemctl --user ...
- guilhas 1y agoThat still depends on systemd, the most privileged deamon in many distros But it is fun to see the marketing 360
- exceptione 1y agoCool, so no PID Eins. I have no shares in systemd, so fine. What do you propose?
- steeleduncan 1y agoPodman seems to have lower memory overhead than Docker. I assume that is a consequence of your point 1