5 ms·
> Specifically for docker it is a very common gotcha that the container runtime can and will bypass firewall rules and open ports anyway. Like I said in anoth
by exceptione 10mo ago
> Specifically for docker it is a very common gotcha that the container runtime can and will bypass firewall rules and open ports anyway.
Like I said in another comment, drop Docker, install podman.
- 3np 10mo agoThis affects podman too.
- jsheard 10mo agoNot if you run it in rootless mode, which is more of a first class citizen in Podman compared to Docker.
- 3np 10mo ago> Not if you run it in rootless mode. Same as for docker, yes? https://docs.docker.com/engine/security/rootless/ https://docs.docker.com/engine/security/rootless/
- exceptione 10mo agonope. You should look at https://docs.docker.com/engine/network/ https://docs.docker.com/engine/network/ Networking is just better in podman.
- joshuaissac 10mo ago> nope. You should look at https://docs.docker.com/engine/network/ https://docs.docker.com/engine/network/ That page does not address rootless Docker, which can be installed (not just run) without root, so it would not have the ability to clobber firewall rules.
- wasmitnetzen 10mo agoRootless exists in Docker, yes, but as OP said, it's not first-class. The setup process is clunky, things break more often. In podman it just works, and podman is leading with features like quadlets, which make docker services just services like any other.
- newsoftheday 10mo agoNo one wants, nor asked for, quadlets.
- figassis 10mo agoIn docker, simply clearly define the interface (ip) and port. It can be 0.0.0.0:80 for example. No bypass happens.
- dns_snek 10mo agopodman is not a drop-in replacement for Docker. You can replace it with podman but expect to encounter minor inconsistencies and some major differences, especially if you use Docker Compose or you want to use podman in rootless mode. It's far from just being a matter of `alias docker=podman`. The only non-deprecated way of having your Compose services restart automatically is with Quadlet files which are systemd unit files with extra options specific to containers. You need to manually translate your docker-compose.yml into one or more Quadlet files. Documentation for those leaves a lot to be desired too, it's just one huge itemized man page.
- kh_hk 10mo agoI keep reading comments by podman fans asking to drop Docker and yet every time I have tried to use podman it failed on me miserably. IMHO it would be better if podman was not designed and sold as a docker drop in replacement but its own thing.
- exceptione 10mo agoThat sucks, I never had any problem running a Dockerfile in podman. I don't know what I do differently, but I would as a principle filter out any container that messes with stuff like docker in docker. Podman doesn't need these kind of shenegians. Also the Docker Compose tool is a well-know exception to the compatibility story. (There is some unofficial podman compose tool, but that is not feature complete and quadlets are better anyway.) I agree with approaching podman as its own thing though. Yes, you can build a Dockerfile, but buildah lets you build an efficient OCI image from scratch without needing root. For those interested, this document¹ explains how buildah compares to podman and docker. 1. https://github.com/containers/buildah/tree/main/docs/containertools https://github.com/containers/buildah/tree/main/docs/contain...
- Nelkins 10mo agoThere's a real dearth of blog posts explaining how to use quadlets for the local dev experience, and actually most guides I've seen seem to recommend using podman/Docker compose. Do you use quadlets for local dev and testing?
- 3np 10mo agoQuadlets aren't what I'd personally use for local dev. They are good for running a local headless persistent service. So I wouldn't use it for your service-under-test but they can be a good fit for supporting dev tools like a local package registry, proxy or VPN gateway. The docs you need for quadlets are basically here: https://docs.podman.io/en/latest/markdown/podman-systemd.unit.5.html https://docs.podman.io/en/latest/markdown/podman-systemd.uni... The one gotcha I can think of not mentioned there is that if you run it as a non-root user and want it to run without logging in as that user, you need to: `sudo loginctl enable-linger $USER`. If you don't vibe with quadlets, it's equally fine to do a normal systemd .service file with `ExecStart=podman run ...`, which quadlets are just convenience sugar for. I'd start there and then return to quadlets if/when you find that becomes too messy. Don't add new abstraction layers just because you can if they don't help. If you have a more complex service consisting of multiple containers you want to schedule as a single unit, it's also totally fine to combine systemd and compose by having `ExecStart=podman compose up ...`. Do you want it to run silently in the background with control over autorestarts and log to system journal? Quadlets/systemd. Do you want to have multiple containers scheduled together (or just prefer it)? Compose. Do you want to manually invoke it and have the output in a terminal by default? CLI run or compose.
- newsoftheday 10mo agoNo, I'm happy with Docker, Docker works very well.
- newsoftheday 10mo agoNothing in the article talked about podman or podman vs docker. Umami with its NexJS and React CVE vulnerability was the issue. BTW, I use Docker because it works extremely well and because there is so much astroturfing from the podman gang I wouldn't use it if my life depended on it until that shit calms down.