If I create a file with certain permission bits in the container, I'd expect the file to be 100% identical when pulling it over to the host, but maybe that's just "legacy" thinking coming from my docker experience?
What about copying files directly between containers, would that change the permissions as well?
The permission bits are metadata on the fs, the file can still be identical.
Plus, how permissions on a file on the container be identical in the host, if e.g. the groups/users are different?
There’s also the ability for podman to run as a system service, and provide an OCI compatible container API. This then integrates seamlessly with the actual docker-compose.
I do that!
It's 99.999% compatible as the podman people basicaly reimplemented all the docker daemon APIs.
It sometimes lags a bit behind, because sometime docker implements new stuff... But for usage with docker-compose it has worked flawlessly for me.
EDIT: you can also export the podman unix socket via socat, i also tried it to run a rootless docker runtime in kubernetes (podman daemon running as a pod, to run docker builds in kubernetes) as an experiment. It works but i'd love to see a better integration with Gitlab runner project.
Gitlab is supposedly getting podman support any time soon, in 15.1 IIRC ?
So like, you can use docker compose for podman instead of docker, instead of something like podman compose?
You have to point your $DOCKER_HOST to the podman unix socket or something, but other than that it’s the actual docker-compose experience. Via the env var trick you could even use the actual docker binary. But you could just alias docker to podman and it works the same, by design!