EDIT: For some context, I recently gave podman another go. I have a few services on my homelab server set up in docker containers, so I tried migrating to podman.

After the second major bug (open issue on github) I encountered looked like it would require completely dropping using compose files to work around, I gave up and went back to docker.

I like the idea of podman, but it’s just not stable. I’ll try again in a year or so.

As a bonus, docker’s CLI is significantly nicer.

  • unitedwithme@lemmy.today
    link
    fedilink
    arrow-up
    161
    arrow-down
    2
    ·
    15 days ago

    I choose Podman bc it’s open source and that’s kind of the reason for using everything as a container bc those are often also open source. Fuck docker

    • Voytrekk@sopuli.xyz
      link
      fedilink
      arrow-up
      59
      ·
      15 days ago

      It also can integrate with Systemd via Quadlets. Let’s you control containers as a sytemd service. I personally use them for my home server and have been happy with it.

      • MoogleMaestro@lemmy.zip
        link
        fedilink
        English
        arrow-up
        22
        ·
        15 days ago

        It does, but it seems like it’s still a bit of an afterthought. But it’s getting better.

        Still tho, podman is fine and I like the project as an alternative to docker.

          • EnsignWashout
            link
            fedilink
            arrow-up
            1
            ·
            14 days ago

            I’ve had the opposite experience. Good to share our data points, though.

      • unitedwithme@lemmy.today
        link
        fedilink
        arrow-up
        6
        arrow-down
        1
        ·
        14 days ago

        So, the Docker engine is free, just not the software under certain stipulations. See I don’t like that. A weird caveat for using it.

          • Kangae_Hishiryo@scribe.disroot.org
            link
            fedilink
            arrow-up
            2
            ·
            14 days ago

            This NOTICE in both repos is weird asf:

            Docker Copyright 2012-2017 Docker, Inc.

            This product includes software developed at Docker, Inc. (https://www.docker.com/).

            This product contains software (https://github.com/creack/pty) developed by Keith Rarick, licensed under the MIT License.

            The following is courtesy of our legal counsel:

            Use and transfer of Docker may be subject to certain restrictions by the United States and other governments. It is your responsibility to ensure that your use and/or transfer does not violate applicable laws.

            For more information, please see https://www.bis.doc.gov/

            See also https://www.apache.org/dev/crypto.html and/or seek legal counsel.

            Also, they do limit some kind of uses if you don’t pay.

            • [object Object]@lemmy.world
              link
              fedilink
              arrow-up
              2
              ·
              14 days ago

              Use and transfer of Docker may be subject to certain restrictions by the United States and other governments. It is your responsibility to ensure that your use and/or transfer does not violate applicable laws.

              That’s true of all software. It may be subject to restrictions by governments. But in this case, it seems to refer to the fact that the US restricted export of cryptographic software, and seemingly continues to restrict. See also Bernstein v. United States.

            • Lena@gregtech.eu
              link
              fedilink
              arrow-up
              2
              ·
              14 days ago

              Also, they do limit some kind of uses if you don’t pay.

              You mean Docker Desktop?

              Also iirc all software developed in the USA is subject to those restrictions.

              • Kangae_Hishiryo@scribe.disroot.org
                link
                fedilink
                arrow-up
                1
                ·
                14 days ago

                …iirc all software developed in the USA is subject to those restrictions.

                Oh, well, I didn’t knew about that, yeah.

                You mean Docker Desktop?

                And, in part yes, but these restrictions also apply to docker-cli and moby, although to a lesser extent

                • Lena@gregtech.eu
                  link
                  fedilink
                  arrow-up
                  1
                  arrow-down
                  1
                  ·
                  14 days ago

                  And, in part yes, but these restrictions also apply to docker-cli and moby, although to a lesser extent

                  What restrictions? The ones on all US software or something else?

      • EnsignWashout
        link
        fedilink
        arrow-up
        2
        ·
        14 days ago

        Docker desktop is not. (open source)

        Which can be a pretty big deal.

        This works out to: The product is unencumbered, but the only reliable installer is encumbered as fuck.

        That’s a “no thanks”, from me.

        I don’t need the sword of “Docker fucking with my colleague’s ability to collaborate” hanging over each of my projects.

        I’m not mad at folks using Docker for backwards compatibility. I just don’t need to make the problem worse.

        • Lena@gregtech.eu
          link
          fedilink
          arrow-up
          2
          ·
          14 days ago

          I found Docker pretty easy to install. Though apparently it’s harder on windows, where they suggest you just use docker desktop, in which case, yeah, fair point. But I’d just put docker in WSL if I had the misfortune of having to use it on Windows.

          • EnsignWashout
            link
            fedilink
            arrow-up
            2
            ·
            13 days ago

            But I’d just put docker in WSL if I had the misfortune of having to use it on Windows.

            Oh, thanks! I might try WSL next time, should I be so unfortunate, again.

          • Mr. Satan@lemmy.zip
            link
            fedilink
            English
            arrow-up
            1
            ·
            12 days ago

            That’s exactly what I’m doing at work. Works a treat especially since I’m fine with CLI.

            Keep in mind that some WSL configuration might be required for better experience — like setting networkingMode to mirrored.


            Sharing code between WSL filesystem and Windows is still somewhat of a hassle.

    • Midnight Wolf@lemmy.world
      link
      fedilink
      English
      arrow-up
      47
      arrow-down
      2
      ·
      15 days ago

      I use docker since it’s what I learned on a decade ago, and my nas that I started from supports docker bit not podman in the ‘app store’. I have three other machines running plain Debian, but I would want everything to work together, y’know? I’ve got a set-and-forget setup and I’d rather not break things without substantial benefit…

      Plus everybody is like ‘it’s the same thing, no learning curve’ but then I start reading up on it and uhoh, learning curves :p

      • definitemaybe@lemmy.ca
        link
        fedilink
        arrow-up
        38
        arrow-down
        2
        ·
        15 days ago

        Plus everybody is like ‘it’s the same thing, no learning curve’ but then I start reading up on it and uhoh, learning curves :p

        Exactly this. I tried podman, as a “container” newb, based on the idea that it’s a (better) drop-in replacement for docker, but it didn’t work. My quick attempts to resolve it went nowhere, and there were no instructions for the container I was trying to spin up for podman to explain the differences required.

        So, in frustration, I decided to try docker and it just worked.

        Good enough for me, for now. I still prefer the idea of not having a daemon running with root privileges, so I’ll likely move over to podman eventually, but I only have so much time to waste tinkering with my setup. And if it ain’t broke, don’t fix it.

        • anyhow2503@lemmy.world
          cake
          link
          fedilink
          arrow-up
          4
          ·
          14 days ago

          In almost all cases podman will work as a drop-in replacement. Problems usually arise from podman not being rootful by default, which does make a difference in most scenarios that involve volume mounts, exposing ports or other kinds of host resource access. You can run podman as root and nowadays even docker as rootless (though at that point you might be better off with podman).

            • Midnight Wolf@lemmy.world
              link
              fedilink
              English
              arrow-up
              3
              ·
              14 days ago

              With every update they warn that any changes made outside the UI may be overwritten (only data in user directories is safe). I have edited a couple config files over the years that have sticked, but they expect the system directories to stay ‘stock’ and warn of data loss or system malfunction if changed. And since it’s my nas it’s a lot of data to be going yolo on, even with backups. Wayyyy to much risk for almost no benefit.

    • diaphragmwp@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      10
      ·
      14 days ago

      Why would you use podman when you could

      #!/bin/ksh
      
      daemon_execdir="/home/etebase/src"
      daemon_logfile="/var/log/etebase"
      daemon="/home/etebase/pyenv/bin/uvicorn"
      daemon_flags="etebase_server.asgi:application --host 159.100.247.89 --port 8000"
      daemon_user="_etebase"
      
      . /etc/rc.d/rc.subr
      
      rc_bg=YES
      rc_reload=NO
      
      pexp="/home/etebase/pyenv/bin/python3 ${daemon} ${daemon_flags}"
      
      rc_start() {
              rc_exec ". ~/.profile; ${daemon} ${daemon_flags} >> ${daemon_logfile} 2>&1"
      }
      
      rc_cmd $1
      
    • tatterdemalion@programming.dev
      link
      fedilink
      arrow-up
      1
      arrow-down
      2
      ·
      14 days ago

      There are still various incompatibilities between the two, and it becomes relevant if you need to work with any organization that has standardized on Docker-specific tooling.

      • esc@piefed.social
        link
        fedilink
        English
        arrow-up
        53
        arrow-down
        1
        ·
        14 days ago

        Rootless, better integrated with system, a bit faster and lighter on resources. Also it supports k8s style yaml configuration both ways and a lot of people are more familiar with them and they also provide some (minimal) interoperability.

        • katze@lemmy.4d2.org
          link
          fedilink
          arrow-up
          10
          arrow-down
          8
          ·
          14 days ago

          a bit faster and lighter on resources.

          Can’t confirm. I have two VMs with an identical image (about 200 MB).

          Docker: Pulling the image takes about 10 seconds and needs about 200 MB diskspace.

          Podman: Pulling the image takes about 15 minutes and needs about 110 GB diskspace.

          Docker: Commands like “docker ps”, “docker stop” etc. run in a few seconds.

          Podman: Commands like “podman ps”, “podman stop” etc. take at least one minute.

          • esc@piefed.social
            link
            fedilink
            English
            arrow-up
            27
            arrow-down
            4
            ·
            14 days ago

            Company confirmed that it is lighter and faster with multiple benchmark at the time of migration. Your case sounds like extreme misconfiguration.

            • katze@lemmy.4d2.org
              link
              fedilink
              arrow-up
              3
              ·
              14 days ago

              extreme misconfiguration

              I did not configure anything, I just installed it from the debian repository.

              • Klara@lemmy.blahaj.zone
                link
                fedilink
                arrow-up
                10
                ·
                14 days ago

                If this is on Debian 12 I think the issue is that the default storage backend is VFS rather than Overlay, which burnt me as well as it is REALLY inefficient. Look up how to find out what you’re using and change it if that’s it. After doing that it’s been really good for me :)

        • lemmyvore@feddit.nl
          link
          fedilink
          English
          arrow-up
          2
          ·
          13 days ago

          Not requiring a service running in root context.

          I don’t think I’ve ever understood the distinction in this argument.

          Isn’t systemd exactly that, a service running in root context?

          I mean yeah you can technically run podman containers by hand as a non-privileged user but nobody does that, let’s be serious. Everybody uses systemd for management and autostart.

          I really don’t understand how running a container through docker as a non-privileged user and dropping all caps is any different from doing the same through systemd + podman.

          Tons of other services do that, ssh, CUPS etc.

          If anybody can explain the difference I’d appreciate it.

      • terminatortwo@piefed.social
        link
        fedilink
        English
        arrow-up
        37
        ·
        15 days ago

        At work, avoiding surprise licensing fees. If you ever have over 250 employees or over 10 million revenue, you owe a subscription.

        At the home, easy orchestration with systemd

  • mlg@lemmy.world
    link
    fedilink
    English
    arrow-up
    60
    arrow-down
    1
    ·
    14 days ago

    Docker became a license nest despite actual devs using k8s like a normal person should.

    Meanwhile podman gave us rootless containers, CDI, and quadlets which far outweighs whatever docker is limping to the barn with.

    • motogo@feddit.dk
      link
      fedilink
      arrow-up
      10
      ·
      14 days ago

      This! Podman rootless quadlets is so powerful and beautifully simple. Just look at that faaar superior security model and hos it doesnt even need a service to manage services because it just integrates natively with systemd I replaced my entire container layer from Rocker Swarm way back with K8s. Then it dawned on me I dont want the pods to move to another node by themselves anyway and then I just moved to Podman quadlets managed Ansible. Oh, and the podman pods are awesome as well.

  • Lian Dynn@lemmy.world
    link
    fedilink
    English
    arrow-up
    39
    ·
    14 days ago

    Podman is unironically the better choice. Just try to make docker comply with your firewall…

    • altphoto@lemmy.today
      link
      fedilink
      arrow-up
      17
      ·
      14 days ago

      Docker bypasses your firewall and runs as root. Only an idiot would allow that shit… I’m an idiot. But I’m fixing that.

      • lemmyvore@feddit.nl
        link
        fedilink
        English
        arrow-up
        3
        ·
        13 days ago

        It doesn’t “bypass your firewall”… it lets you shoot yourself in the foot. You’re asking it to open ports without specifying an explicit network interface so it opens them on all interfaces. Which includes opening up the firewall, because what’s the point of putting up a service and blocking it in the firewall.

        Also, doing it by hand would be incredibly tedious. Docker automatically adjusts the rules to match the ports and interfaces to its private container netmasks, and brings them up or down as needed when the containers start/stop.

        All you have to do is bind ports to localhost or to a private interface if you don’t want the service to be publicly exposed.

        Beginners get bitten by this because they say ports: 9999:9999 instead of ports: 127.0.0.1:9999:9999/tcp like they should. Unfortunately most examples out there use the terse version and never explain why it’s bad.

    • WolfLink@sh.itjust.worksOP
      link
      fedilink
      arrow-up
      2
      arrow-down
      1
      ·
      13 days ago

      Podman is unironically the better choice.

      I like the idea of podman, but it’s just not stable. This meme was inspired by my frustration of trying to switch.

      Just try to make docker comply with your firewall.

      I literally did this yesterday and it wasn’t that hard. You just add iptables:False to the docker config file.

  • lengau@midwest.social
    link
    fedilink
    arrow-up
    28
    ·
    14 days ago

    I’m curious why you feel this way? I’m kinda the opposite — podman has features I use that Docker doesn’t.

    • todotoro@midwest.social
      link
      fedilink
      English
      arrow-up
      9
      ·
      14 days ago

      Not the poster, but I kinda get this sentiment. For my laptop and things that I do for work, I prefer Podman. Better security posture out of the box, and I’m typically crafting my own pods to work a specific way.

      But, if I am just trying to start up some app/service and I’m following the GitHub documentation with the project…I want to just copy and paste and there isn’t a 1-for-1 for docker compose. Podman does have an alias package so you can say docker on the cli, but the “compose” part of it is not as good if I just want something to run without dicking with it.

      So in short, if I’m making something with a container or want to have hands on control, I prefer Podman. If I’m running something “off the shelf”, like just running someone’s docker compose files files from their Github, I’m just running Docker man.

      • Lian Dynn@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        14 days ago

        I use the docker compose plugin with podman and it’s the same. My compose stack is massive with tons of services and I migrated it from docker to podman with no issues.

    • WolfLink@sh.itjust.worksOP
      link
      fedilink
      arrow-up
      1
      ·
      13 days ago

      This meme was inspired by my frustration from trying to switch. I like the idea of podman, but it just doesn’t work. Tbf the bugs I encountered this time were with podman compose rather than podman itself, but still, I’d rather use the tools that work. I’ve had similar experiences when I’ve tried to switch to podman in the past.

      • lengau@midwest.social
        link
        fedilink
        arrow-up
        1
        ·
        13 days ago

        Interesting. I don’t use any of the compose tools, so I’ve not faced that. I find Podman works reliably in places where I can’t even get Docker to start working (such as RISC-V machines), but I also typically use podman for testing before deploying to k8s

    • mushroommunk@lemmy.today
      link
      fedilink
      arrow-up
      2
      ·
      14 days ago

      That’s what I was thinking. I’ve barely ever understood it for deployments for large companies (even then I disagree, I think it’s added overhead just to bypass poor processes) but at home? Nah, install everything together.

  • LiveLM@lemmy.zip
    link
    fedilink
    English
    arrow-up
    17
    ·
    14 days ago

    Ngl after trying out Rootless Podman on my system (I was playing with Distrobox) I kinda wanna switch my whole Homelab to it, I’m just lazy, afraid the move to rootless with blow up everything and have zero fucking free time.

    • porkloin@lemmy.world
      link
      fedilink
      English
      arrow-up
      16
      ·
      14 days ago

      I am running my entire homelab from podman quadlets (systemd managed podman containers) and it’s honestly very dope. Podman gets a bad rap for being second tier to docker but they legit have a bunch of awesome features for Linux users specifically that make it way nicer. Using systemd for docker status can add some misdirection occasionally, but having the logs from containers directly in journalctl alongside the rest of my system logs is amazing

      • CallMeAl (like Alan)@piefed.zip
        link
        fedilink
        English
        arrow-up
        5
        arrow-down
        1
        ·
        14 days ago

        I don’t know how you would even compare them. Quadlets can do what Docker Swarm or Kube does with dynamic instances and dependency lifecycle management. Docker Compose doesn’t have nearly the same features as Podman Quadlet.

        • hirihit640@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          2
          ·
          14 days ago

          Docker swarm uses compose files too. But really, when you have tools like Podlet that converts compose files to quadlets, it’s a pretty good sign that the two fit 90% the same use cases.

          • CallMeAl (like Alan)@piefed.zip
            link
            fedilink
            English
            arrow-up
            1
            ·
            14 days ago

            I think its more than Compose does a small subset of what Quadlets can do. I can understand why if your only use case is Compose and you already like it, why change? For me, the rootless by default and daemonless nature of podman quadlets, and its clean design all make it the preferred choice.

            • hirihit640@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              1
              ·
              14 days ago

              Podman-compose also works rootless and without a daemon. Naturally since it’s daemonless, it does require a separate systemd service if you want services to automatically restart (I forget exactly what that systemd service is called).

              What do you mean by “clean design”? This is of course subjective but I just want to understand quadlets more.

              • CallMeAl (like Alan)@piefed.zip
                link
                fedilink
                English
                arrow-up
                1
                ·
                13 days ago

                What do you mean by “clean design”?

                If you are comfortable reading the source code for each project that is the most revealing way to see the difference.

                In short, Docker has a lot more code because it duplicates a lot of kernel and systemd functionality (often poorly), uses multiple components that communication over grpc with each other to do things, requires setuid binaries, and defaults to running everything as root.

                Podman, is a straight forward clean simple program that fully uses kernel and systemd interfaces rather than duplicating functionality. Quadlet is build on systemd generators and its use of templates via systemd instances lets you use deterministic dynamic configuration in ways that is unlike anything in Docker.

                • hirihit640@sh.itjust.works
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  13 days ago

                  If you are comfortable reading the source code for each project that is the most revealing way to see the difference.

                  Strongly disagree on this. Design can mean many different things. For example in the docker vs podman explanation you gave, you are talking about integration with Linux and adherence to Linux standards, and I agree that with you on that. That’s one of the reasons I do prefer Podman over Docker.

                  However when I think about “clean” in regards to podman-compose vs Quadlet, I think about the user/developer experience. Quadlets integrate with systemd, but as a consequence inherit the design and interfaces of systemd. This means putting Quadlet files into a global systemd folder. This makes GitOps harder since all your projects get combined into a single folder. Also I’m not a fan of how verbose systemd config format is, like the repetition of keys. Seeing PublishPort= repeated for every port mapping looks ugly imo. And every service needs to be defined in a separate file, even if some services are only a few lines of config. Which makes it harder to see all services at a glance.

                  I recognize this is all my subjective preferences, but this is just what I think when I hear “design”.