EDIT: For some context, I recently gave podman another go. I have a few services on my homelab server set up in docker containers, so I tried migrating to podman.

After the second major bug (open issue on github) I encountered looked like it would require completely dropping using compose files to work around, I gave up and went back to docker.

I like the idea of podman, but it’s just not stable. I’ll try again in a year or so.

As a bonus, docker’s CLI is significantly nicer.

  • unitedwithme@lemmy.today
    link
    fedilink
    arrow-up
    147
    arrow-down
    1
    ·
    1 month ago

    I choose Podman bc it’s open source and that’s kind of the reason for using everything as a container bc those are often also open source. Fuck docker

    • Voytrekk@sopuli.xyz
      link
      fedilink
      arrow-up
      56
      ·
      1 month ago

      It also can integrate with Systemd via Quadlets. Let’s you control containers as a sytemd service. I personally use them for my home server and have been happy with it.

      • ArchAengelus@lemmy.dbzer0.com
        link
        fedilink
        arrow-up
        23
        arrow-down
        2
        ·
        edit-2
        1 month ago

        The learning curve for quadlets is quite harsh in my opinion. I started with podman compose 3 years ago for my homelab, because it allowed user containers.

        I tried to migrate to quadlets unsuccessfully, several times over the years. it was only recently that my self-hosted Qwen was capable enough to figure out where I was messing up and automate the process a bit.

        I probably wasn’t sufficiently motivated. It felt like podman compose is basically docker compose, but quadlets are a quite a bit different in form and function, so I was never able to grok them:

        • Voytrekk@sopuli.xyz
          link
          fedilink
          arrow-up
          21
          ·
          1 month ago

          There is a tool named Podlet that can help translate to quadlets. I was able to fully translate my unraid and compose setups to quadlets.

            • Voytrekk@sopuli.xyz
              link
              fedilink
              arrow-up
              2
              ·
              1 month ago

              I migrated from docker containers on Unraid to using quadlets on RockyLinux. The Podlet utility helped a bit with taking an existing docker container and converting it to a quadlet. Also did thorough testing in a VM before swapping my server.

              • pjusk@lemmy.dbzer0.com
                link
                fedilink
                English
                arrow-up
                1
                ·
                1 month ago

                Interesting, just migrated away from Unraid myself. But chose Proxmox -> Debian -> Podman Containers instead. Any reason in particular you chose Rocky?

                • Voytrekk@sopuli.xyz
                  link
                  fedilink
                  arrow-up
                  1
                  ·
                  1 month ago

                  The security of Rocky is solid and RL 10 is supported for quite a long time. I’m also used to RHEL based systems at work, as we target Red Hat.

                  That being said, I wouldn’t recommend it for most people. SELinux can be annoying to deal with and can cause issues where it isn’t obvious that SELinux is the cause.

                  If I were to chose again, I would probably just pick Debian as most of my workloads are just running in containers or VMs. The only services running on the host are NFS and Samba.

          • hirihit640@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            1
            ·
            1 month ago

            I remember trying it and my compose files blew up to multiple Quadlet files with a much larger total size (lines of code). I find that compose is just more concise and structured compared to Quadlets.

            • Voytrekk@sopuli.xyz
              link
              fedilink
              arrow-up
              4
              ·
              1 month ago

              It does have a larger file size compared to compose, sure. The big advantage of quadlets is that systemd will handle things in the event of a failure. It makes it a great option for production environments where you will not need to update your config files as much. It also allows you to have more control over when each application starts, if they rely on a specific disk mount or service running on the system. I’m sure someone else can provide more benefits who use them in a production environment.

              • hirihit640@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                1
                ·
                1 month ago

                Fair enough. My requirements are simply: start all services when the machine has finished booting. And I can’t remember the last time my system failed. Most that happened was a power outage, and Quadlets wouldn’t have helped there either.

                So in my case I much prefer simple and easy-to-read configs, over the complexity of integrating with systemd.

                • Voytrekk@sopuli.xyz
                  link
                  fedilink
                  arrow-up
                  1
                  ·
                  1 month ago

                  Docker compose definitely works for most people, so I would feel pressured to swap.

                  There is one instance where Quadlets would have fixed an issue we ran into at work. We had a Kafka instance whose container died and went away because we ran out of space on the server. Compose doesn’t recreate containers on failure, so I was called in to fix the issue. Quadlets treats containers as disposable, so it would have recreated it as soon as it went away. The root of the issue was a bad logging config that we fixed on the next business day.

      • MoogleMaestro@lemmy.zip
        link
        fedilink
        English
        arrow-up
        21
        ·
        1 month ago

        It does, but it seems like it’s still a bit of an afterthought. But it’s getting better.

        Still tho, podman is fine and I like the project as an alternative to docker.

    • Midnight Wolf@lemmy.world
      link
      fedilink
      English
      arrow-up
      45
      arrow-down
      1
      ·
      1 month ago

      I use docker since it’s what I learned on a decade ago, and my nas that I started from supports docker bit not podman in the ‘app store’. I have three other machines running plain Debian, but I would want everything to work together, y’know? I’ve got a set-and-forget setup and I’d rather not break things without substantial benefit…

      Plus everybody is like ‘it’s the same thing, no learning curve’ but then I start reading up on it and uhoh, learning curves :p

      • definitemaybe@lemmy.ca
        link
        fedilink
        arrow-up
        36
        arrow-down
        1
        ·
        1 month ago

        Plus everybody is like ‘it’s the same thing, no learning curve’ but then I start reading up on it and uhoh, learning curves :p

        Exactly this. I tried podman, as a “container” newb, based on the idea that it’s a (better) drop-in replacement for docker, but it didn’t work. My quick attempts to resolve it went nowhere, and there were no instructions for the container I was trying to spin up for podman to explain the differences required.

        So, in frustration, I decided to try docker and it just worked.

        Good enough for me, for now. I still prefer the idea of not having a daemon running with root privileges, so I’ll likely move over to podman eventually, but I only have so much time to waste tinkering with my setup. And if it ain’t broke, don’t fix it.

        • anyhow2503@lemmy.world
          link
          fedilink
          arrow-up
          3
          ·
          1 month ago

          In almost all cases podman will work as a drop-in replacement. Problems usually arise from podman not being rootful by default, which does make a difference in most scenarios that involve volume mounts, exposing ports or other kinds of host resource access. You can run podman as root and nowadays even docker as rootless (though at that point you might be better off with podman).

    • diaphragmwp@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      7
      ·
      1 month ago

      Why would you use podman when you could

      #!/bin/ksh
      
      daemon_execdir="/home/etebase/src"
      daemon_logfile="/var/log/etebase"
      daemon="/home/etebase/pyenv/bin/uvicorn"
      daemon_flags="etebase_server.asgi:application --host 159.100.247.89 --port 8000"
      daemon_user="_etebase"
      
      . /etc/rc.d/rc.subr
      
      rc_bg=YES
      rc_reload=NO
      
      pexp="/home/etebase/pyenv/bin/python3 ${daemon} ${daemon_flags}"
      
      rc_start() {
              rc_exec ". ~/.profile; ${daemon} ${daemon_flags} >> ${daemon_logfile} 2>&1"
      }
      
      rc_cmd $1
      
    • tatterdemalion@programming.dev
      link
      fedilink
      arrow-up
      1
      arrow-down
      2
      ·
      1 month ago

      There are still various incompatibilities between the two, and it becomes relevant if you need to work with any organization that has standardized on Docker-specific tooling.

  • mlg@lemmy.world
    link
    fedilink
    English
    arrow-up
    58
    arrow-down
    1
    ·
    1 month ago

    Docker became a license nest despite actual devs using k8s like a normal person should.

    Meanwhile podman gave us rootless containers, CDI, and quadlets which far outweighs whatever docker is limping to the barn with.

  • Lian Dynn@lemmy.world
    link
    fedilink
    English
    arrow-up
    31
    ·
    1 month ago

    Podman is unironically the better choice. Just try to make docker comply with your firewall…

    • altphoto@lemmy.today
      link
      fedilink
      arrow-up
      14
      ·
      1 month ago

      Docker bypasses your firewall and runs as root. Only an idiot would allow that shit… I’m an idiot. But I’m fixing that.

      • lemmyvore@feddit.nl
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 month ago

        It doesn’t “bypass your firewall”… it lets you shoot yourself in the foot. You’re asking it to open ports without specifying an explicit network interface so it opens them on all interfaces. Which includes opening up the firewall, because what’s the point of putting up a service and blocking it in the firewall.

        Also, doing it by hand would be incredibly tedious. Docker automatically adjusts the rules to match the ports and interfaces to its private container netmasks, and brings them up or down as needed when the containers start/stop.

        All you have to do is bind ports to localhost or to a private interface if you don’t want the service to be publicly exposed.

        Beginners get bitten by this because they say ports: 9999:9999 instead of ports: 127.0.0.1:9999:9999/tcp like they should. Unfortunately most examples out there use the terse version and never explain why it’s bad.

    • WolfLink@sh.itjust.worksOP
      link
      fedilink
      arrow-up
      2
      arrow-down
      1
      ·
      1 month ago

      Podman is unironically the better choice.

      I like the idea of podman, but it’s just not stable. This meme was inspired by my frustration of trying to switch.

      Just try to make docker comply with your firewall.

      I literally did this yesterday and it wasn’t that hard. You just add iptables:False to the docker config file.

    • mushroommunk@lemmy.today
      link
      fedilink
      arrow-up
      2
      ·
      1 month ago

      That’s what I was thinking. I’ve barely ever understood it for deployments for large companies (even then I disagree, I think it’s added overhead just to bypass poor processes) but at home? Nah, install everything together.

    • cunnililgus@sopuli.xyz
      link
      fedilink
      arrow-up
      4
      arrow-down
      1
      ·
      1 month ago

      It doesn’t and I’m sure there are benefits, but for basic home services daemonless translated directly into more work for no benefit.

        • cunnililgus@sopuli.xyz
          link
          fedilink
          arrow-up
          2
          arrow-down
          1
          ·
          1 month ago

          Definitely, but then it feels like it comes with a cost rather than benefit of not having a daemon. You gain more control at the cost of convenience.

          • pjusk@lemmy.dbzer0.com
            link
            fedilink
            English
            arrow-up
            2
            ·
            1 month ago

            Keyword there being “feel”. Cos it certainly does add security. Imo quadlets are easier to understand and write than compose files too, but to each thwir own ofc. Most important thing here is to work with what feels the most natural and making the best out of it 👍

            • cunnililgus@sopuli.xyz
              link
              fedilink
              arrow-up
              1
              ·
              1 month ago

              I understand that to admins or experienced users service files probably feel like home. To an inexperienced user like me it added quite a lot of friction, especially compared to docker where I pretty much copy the compose file and run it.

              I tried to use podman instead of docker, but decided that for my home use it might not be worth the headache, but I might reconsider now that I could use LLM to set those up for me.

  • LiveLM@lemmy.zip
    link
    fedilink
    English
    arrow-up
    16
    ·
    1 month ago

    Ngl after trying out Rootless Podman on my system (I was playing with Distrobox) I kinda wanna switch my whole Homelab to it, I’m just lazy, afraid the move to rootless with blow up everything and have zero fucking free time.

    • porkloin@lemmy.world
      link
      fedilink
      English
      arrow-up
      15
      ·
      1 month ago

      I am running my entire homelab from podman quadlets (systemd managed podman containers) and it’s honestly very dope. Podman gets a bad rap for being second tier to docker but they legit have a bunch of awesome features for Linux users specifically that make it way nicer. Using systemd for docker status can add some misdirection occasionally, but having the logs from containers directly in journalctl alongside the rest of my system logs is amazing

  • RVGamer06@sh.itjust.works
    link
    fedilink
    arrow-up
    8
    ·
    1 month ago

    y’all use containers still? I run my site with native installed software configured by hand like a TRUE sysadmin!