EDIT: For some context, I recently gave podman another go. I have a few services on my homelab server set up in docker containers, so I tried migrating to podman.

After the second major bug (open issue on github) I encountered looked like it would require completely dropping using compose files to work around, I gave up and went back to docker.

I like the idea of podman, but it’s just not stable. I’ll try again in a year or so.

As a bonus, docker’s CLI is significantly nicer.

  • Lian Dynn@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 day ago

    Podman is unironically the better choice. Just try to make docker comply with your firewall…

    • WolfLink@sh.itjust.worksOP
      link
      fedilink
      arrow-up
      0
      ·
      10 hours ago

      Podman is unironically the better choice.

      I like the idea of podman, but it’s just not stable. This meme was inspired by my frustration of trying to switch.

      Just try to make docker comply with your firewall.

      I literally did this yesterday and it wasn’t that hard. You just add iptables:False to the docker config file.

    • altphoto@lemmy.today
      link
      fedilink
      arrow-up
      0
      ·
      24 hours ago

      Docker bypasses your firewall and runs as root. Only an idiot would allow that shit… I’m an idiot. But I’m fixing that.

      • lemmyvore@feddit.nl
        link
        fedilink
        English
        arrow-up
        0
        ·
        15 hours ago

        It doesn’t “bypass your firewall”… it lets you shoot yourself in the foot. You’re asking it to open ports without specifying an explicit network interface so it opens them on all interfaces. Which includes opening up the firewall, because what’s the point of putting up a service and blocking it in the firewall.

        Also, doing it by hand would be incredibly tedious. Docker automatically adjusts the rules to match the ports and interfaces to its private container netmasks, and brings them up or down as needed when the containers start/stop.

        All you have to do is bind ports to localhost or to a private interface if you don’t want the service to be publicly exposed.

        Beginners get bitten by this because they say ports: 9999:9999 instead of ports: 127.0.0.1:9999:9999/tcp like they should. Unfortunately most examples out there use the terse version and never explain why it’s bad.