podman is almost AFAIK 1:1 compatible with docker, the team does great work on it
welcome to fedora!
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.
Beginning of January 1st 2024 this rule WILL be enforced. Posts that are not tagged will be warned and if not fixed within 24h then removed!
podman is almost AFAIK 1:1 compatible with docker, the team does great work on it
welcome to fedora!
Yes, it is! If you just run alias docker=podman
, you won't even have to remember that you're running Podman, and not Docker.
I am still having problems with SELinux, though, so I have just turned it to permissive. Any guides for that?
Is it possible to connect docker / podman directly to the router? I'm operating an L2 bridge https://developers.redhat.com/articles/2022/04/06/introduction-linux-bridging-commands-and-features systemd-nspawn containers can connect to my router directly, but how to do it with docker / podman?
I originally excited by Podman, but ultimately migrated away from it. Friendship ended with Ubuntu and Docker -> CentOS and Podman -> Proxmox + Debian LXC (which has its own irritations but anyway). Off the top of my head:
I brought all this up in another community and was told the problem was [paraphrased] "people keep trying to use Podman like they use Docker" - whatever that means. I do like a number of design choices in it, like including the command used to create containers in the metadata, and how it's easy to integrate into SystemD for things like scheduled updates.
Cockpit is pretty slick though, need to install it on my bare metal Debian host.
how do you use proxmox + debian lxc?
I use that too, but run services + caddy reverse proxy with docker compose inside
I've read that docker should not be used inside containers, but it has worked for me. I have wireguard in a VM, I think I had some issues there
Mostly just as a wrapper for Docker. The main issue I've run into is Docker's union file system functionality doesn't work when backed by ZFS, so disk usage can balloon out of control. I wouldn't use this in production but don't tell me how to live my life mom.
Beyond various Docker stacks I also have a Certbot container that uses Snap (sigh), and Hashicorp Vault container which runs as a vanilla SystemD service. I run Wireguard as part of my OPNSense VM. That's something I would run in a VM since it's exposed to the internet. I have an older MinIO and Concourse CI Docker Compose config that I'd love to run in LXC but I suspect that isn't realistic.
Note on Vault, I haven't been able to get mlock to work (used to prevent sensitive memory from being swapped). By all accounts it should just work in LXC, but since it isn't and there's no swap on the host I just turned it off. I may migrate Vault to a VM at some point.
I'm personally just interested in lightweight environments with good enough isolation and don't break all the time over nothing. Docker mostly accomplishes that for me. LXC + Docker also mostly accomplishes that.
(My heart yearns for FreeBSD Jails but with decent tooling)
I use Docker inside Debian LXC on Proxmox, there’s a way to avoid the crazy disk usage and it works really nicely. I followed these blog posts:
https://theorangeone.net/posts/docker-in-lxc/
https://theorangeone.net/posts/docker-lxc-storage/
I’m certainly not using it in production but it’s great in the home lab.
Tangential to the main subject here, Cockpit is awesome and everyone should be using it. You don't have to be on a Red Hat distro either, it works beautifully on Ubuntu or Debian or whatever else you're running. The log viewer and PCP integration (for performance metrics) are particularly standout features.
I also highly recommend the Navigator plugin from 45Drives, which adds a complete file browser and simple text file editor.
Judging by the screenshots, this looks very similar to Portainer. Are they basically the same tool set for different container architectures? Looks pretty interesting.
Podman replaces the underlying container engine (the docker component). Portainer is a webUI that sits on top of Docker and provides you with tools to manage it. The Podman plugin for Cockpit just happens to do the same thing.
You can actually use Portainer with Podman if you want to. It's a little fiddly to set up, but it works.
The main advantage of Podman is that it's rootless by default, whereas rootless Docker is still a somewhat tricky beast to set up.
Welcome on board :)
I documented a bit how to run Lemmy via Podman here: https://f-hub.org/Solarpunk/lemmy-podman
Thanks for sharing! I think I'll implement the alias in the near future once I get more comfortable w/ Docker
I started with podman and wanted to like it. Ultimately moved to docker because of docker compose
Compose works with podman too, you just need podman system service & to set the DOCKER_HOST env var to it's socket.
So that's why my containers aren't restarting automatically on boot. Thanks!
Why would you move to a red hat product?
Because some people want to play with the stuff they have to support at work?
Because the RHEL ecosystem is enormous and heavily used in the enterprise?
Because some people get free licenses?
Because not everybody shares your priorities?