Podman Desktop: A Free OSS Alternative to Docker Desktop
podman-desktop.io
podman-desktop.io
--platform linux/arm64
argument with Docker Desktop and that seems to be working for them.I also never understood the justification for the added complexity it created, but I also don't have a dedicated ops team at my job to solve my problems.
I like the fact that I decide when I upgrade, not Docker Desktop nagging me every week.
The higher ups eventually let us just buy docker desktop and we are all happier now.
Looks like there's an `colima start --network-address`. I just spent the day trying to get a docker vm I can ping directly.
As a bonus, you can install the Docker CLI (e.g. `brew install --formula docker`) and use that to interact with any containers you start with colima.
At what point did containerization begin to make sense for your workflow?
For personal use I found it great and lighter than Docker Desktop. At work, unfortunately all options but Docker Desktop have issues with either 1) Our Cisco AnyConnect VPN, or 2) Our authenticated http proxy. Couldn't find anything else providing a container runtime + a local k8s on MacOS that works in this environment. So we just got Docker Desktop licenses.
Rancher desktop works seamlessly with docker-compose. No issues at all.
Getting Podman to run CUDA/Nvidia workloads was a bit more challenging, but that can also be done.
I don't know what Docker Desktop is doing but on a top end i9 with 128gb of ram it still takes 60 seconds to start
and the UI takes forever to do anything
it makes Teams look responsive
> https://www.docker.com/blog/the-magic-behind-the-scenes-of-d...
> https://docs.docker.com/desktop/install/linux-install/
> https://docs.docker.com/desktop/faqs/linuxfaqs/#what-is-the-...
"Docker Desktop on Linux runs a Virtual Machine (VM) so creates and uses a custom docker context desktop-linux on startup." I had previously assumed it would be native on Linux, but apparently not. To be clear, this only applies when talking about "Docker Desktop" installations - not the same thing as "docker" etc etc.
I also think the performance is pretty bad, and I've used it on all three OSes at one time or another. I simply never install "Docker Desktop" on Linux typically anyway - it adds so little value over a basic native local docker install there.
The only thing I think "Docker Desktop" is really great at is creating FUD regarding using the alternatives or even plain ole free "docker", but that is probably its primary means of generating revenue for the company - I've seen docker desktop licences get deployed everywhere recently, regardless of the merits. So many users I encounter don't even understand the distinction now between docker/docker-desktop, or that there is one.
Also known as a VM, but maybe you get better warm up times. My main complaints are with the "docker desktop" app experience - not so much "docker" itself VM or otherwise. It adds so little to docker for the license cost too, at least so far.
https://learn.microsoft.com/en-us/windows/wsl/compare-versio...
You can simply install docker in a VM/WSL2 natively yourself and avoid docker desktop/licensing altogether. "Docker Desktop" is/was really a tool to simplify getting a Linux Kernel (the critical dependency for cross-platform container dev) on non-Linux platforms IMO, which seems wild to pay for to me in its current state and when Windows has a great built in VM via WSL2 anyway. That it even exists on Linux now (recent addition) is kinda amusing - on MacOS and Windows there is at least some argument to be made it simplifies getting the kernel...
I actually decided today to stop using DD on my Windows machine and just run docker native inside the WSL2 VM instance instead. Still not sure what solution I'm going for on my Mac.
The initial setup was a little more complex than just running Docker Desktop, but since then, it's running flawlessly.
Also, there are many people who want that VM boundary. We found this when designing for Linux in Rancher Desktop and talking with people about it.
A lot of delays has to do with starting VMs. You need this for Linux on Mac/Windows.
Disclaimer: I started Rancher Desktop. I might be biased.
This is considered good?
alias docker=nerdctl
After removing that alias everything worked first try with Docker Desktop. However after starting up a couple of Dev containers and some debugger my machine crawled to a halt and was memory swapping like there was no tomorrow. I found that this behavior could be normal for Docker Desktop. So I think I'm going to switch back to Rancher Desktop (or perhaps Podman Desktop) sooner than later.Sorry for using this comment as a way to get ahold of you but there is no DM function on HN and the comment I was wondering about was posted by you 18 days ago and the comments are locked now.
Here is the comment in question: https://news.ycombinator.com/item?id=33347058
I have been controlling my water heater with HA for a few months and I too am risk averse when it comes to legionella. You have taken it to another level by replacing the sensor inside with a DS18B20. I was also interested in doing this but I don't really want to drill into it. How did you install the sensor? Is the water not under pressure? I've just measured water temperature at the tap with a meat thermometer and under flow into a container to determine that the temperature falls in the range that is safe for legionella growth. Would love to look into a proper sensor again if you have any information about that.
Again, sorry for hijacking your completely unrelated comment.
First of all, I'm also concerned by legionella growth. However all the sources I can find suggests that at a legionella run above 60 degrees celsius once a week should be enough to kill all bacteria. So that's what I'm doing.
My sensor installation was extremely easy. My warm water heater is in fact a barrel within a barrel. And some insulation material between those barrels. If it would only be metal, you lose too much heat. In the outside barrel (excuse me for lack of a better term) there was an analogue thermometer. This thermometer has a metal back so it makes direct contact with the inside barrel. I just pulled this one out and replaced it with a DS18B20 probe. Again metal against metal, so maximum contact.
Finally I have calibrated the sensor by running it with hot water at the tap and measuring the temperature both there and on the warm water heater (with 2 DS18B20). I've done this for several temperatures with intervals of 10 degrees. I've ignored possible sensor deviations. Finally I used Excel's INTERCEPT and SLOPE functions on the range to calculate the value needed for a linear equation. I have used the formula:
boiler_temperature * SLOPE + INTERCEPT
My math is probably far from perfect and I might revisit it one day. But it works for me currently. I also visualized the measurement results with my calculations and they seem to be pretty accurate. Especially when accounting for missing measurements.I've also added my personal page to the 'About me' on here, and I have the same Reddit username if you want to DM me there.
This is where those extensions (or native Firefox) is good for auto-sleeping tabs you haven't looked at in the last 10-20min. Saves so much CPU.
Currently at 220 in one window, 350 in another, and eight in a third.
Docker desktop pays for itself by solving these issues though IMO (I wasn't able to get a licence at the old role however)
I am the teamlead of CRC and work on the Windows enablement of podman machine, with the podman desktop team. Gladly take questions here or by email.
(*) also known as wsl-vpnkit
Does anyone know how well Podman performs on Mac? Especially file sharing.
Edit: A quick Google led me back to this HackerNews comment[1]. Looks like Docker for Mac is faster.
[0] https://www.docker.com/blog/speed-boost-achievement-unlocked...
You can try running https://github.com/crc-org/crc with the podman preset (!) to test it. It would not be exactly the same how podman machine will use it eventually, but might help to give an idea of performance or issues we can improve on. We have seen a lot of users being more than content as it also works in a vpn environment. Note that the CRC tool primarily aims at OpenShift deployment... This is a different preset (resource intensive). Only available as an installer with our tray (sorry about this).
The driver we use is https://github.com/crc-org/vfkit and I am sure Christophe could share a method to just run the VM with our driver. HMU by email if you prefer.
The solution Vivek and Sergio work on is https://gitlab.com/virtio-fs/virtiofsd
I was surprised to find out wsl2 now supports systemd
https://devblogs.microsoft.com/commandline/systemd-support-i...
I was able to install docker normally inside wsl2 and it worked perfectly. No "desktop" app needed. This will be a game changer when it hits GA
We are looking into enabling systemd, though as said, this isn't GA yet. The functionality would only work for Win11, so we have to enable a win10 workaround for this (we have), but this has to be based on feature detection.
Arm binaries is being looked at, but can't commit to a timeframe when this will be delivered.
If you dont mind some tinkering, a fedora Aarch64 container base image can be imported to wsl2 to install podman.
You can install Docker following their Linux guide and then in your shell's profile file add:
if grep -q "microsoft" /proc/version &>/dev/null; then
if service docker status 2>&1 | grep -q "is not running"; then
wsl.exe --distribution "${WSL_DISTRO_NAME}" --user root \
--exec /usr/sbin/service docker start >/dev/null 2>&1
fi
fi
Basically the first time you open a terminal it'll pause for 5 seconds while the Docker daemon is started but it'll stay started for the duration of your Windows uptime even if you close your terminal. The next time you open a terminal it'll be instant.The experience is light-years ahead of the monstrosity that is Docker Desktop
Will check if we need to change the docs.
But your recommendation remains. Better to use the latest release as indicated on the GitHub releases of podman. These have seen more tests and integration use/tests
Alternatively you can run `podman machine` which sets up a VM with the stable version.
That contention is heavily dependent upon how Docker was installed. Docker desktop, yes. Command line Docker on Linux? That used to be much more complicated and depended on if you had an OS vendor provided version or had a Docker provided repo install.
RHEL’s repo version always seemed particularly out of date to me.
sudo dnf copr enable rhcontainerbot/podman-next -y
sudo dnf install podman
However the versions provided by the distro have gone through more tests. We are still improving this part as ideally you should be able to pick a version
Podman has no control on this. Each Linux distribution deals with packaging in its own way. If this packaging is not to your taste, podman can easily be installed from alternatives sources: unofficial deb packages, or plain binaries.
BTW, podman v4 is in debian/experimental. I don't know why it didn't land into unstable yet.
> This isn't a problem with Docker, which has tight control over what is deployed.
AFAIK, Docker (now Moby) has no control over what is packaged in Debian/Ubuntu (unless the Debian maintainer works for Moby?). If you install Docker from the official Debian repositories, the "docker" package is an alias for "docker.io", which is a version 20.10.19 in debian/unstable. The latest 20.10.21 is not yet packaged by Debian.
Maybe I can try again, but it was frustrating enough to turn me away for a while.
Docker bypasses this essentially because it uses root privs to set up the port forwarding rules.
[1]: https://www.kernel.org/doc/html/latest/networking/ip-sysctl.... -> ip_unprivileged_port_start
In my experience, if you need to bind to < 1024 ports, just run the container as root. Also if you want finer-grained control of host-side permissions of your mounts (i.e. map host uid 1000 to container uid 99). Otherwise rootless is fine.
I did a quick test and it works ok for me to bind to low numbered ports just passing that param to podman run.
So basically you're left deploying a container and waiting for something to break, then inspecting SE logs and patching rules in (and folding all that back into your ansible or whatever).
Maybe this is OK if its your application and you can dump it on a staging environment and push it through your 100% coverage end to end test suite to capture all requirements, but if its a third party - or maybe your test coverage isn't quite where you want it to be - you're basically walking out on the rope bridge blind.
Not sure there is really a way to solve that. Perhaps it there was a `pledge`/`unveil` like system where all requirements can be discovered up front... Otherwise it felt like yours stuck running in SEDisable or SEPermissive for months collecting data (after every deploy).
Maybe I just missed an obvious route to disable swaths of SELinux for rootless containers - where it probably doesn't have as much of an application.
Sorry Dan Walsh :(
Yeah you can put container_t into permissive mode:
# semanage permissive -a container_t
AVC denials will still be logged but the operations won't be denied.
Some other useful sources of info - the container_selinux man page tells you about container_t. And an index of Dan Walsh's blog posts about containers & SELinux can be found in the README of <https://github.com/containers/container-selinux>.
And of course the RHEL documentation for creatign custom SELinux policies that inherit from container_t (for instance, I use it to allow processes within a container to read their certificates out of /etc/pki/tls which is normally forbidden. It's documented here: https://access.redhat.com/documentation/en-us/red_hat_enterp...
podman run --security-opt label=disable
https://github.com/containers/podman/blob/main/troubleshooti... Note: Labeling can be disabled for all containers by setting label=false in the containers.conf(5) file.
https://docs.podman.io/en/latest/markdown/podman-run.1.html#...But more secure way would be to add ":z" or ":Z" to volume and podman will auto-relabel source dir. Finally you can use nuclear option: "--privileged". It's still more secure than docker's one because you are limited by your user's capabilities.
So if you're just using it for yourself you probably don't need to bother
I'm curious on which Linux did you encounter issues while installing Docker? I cannot comment on the (to me somewhat pointless) Docker Desktop GUI installation on Linux, but I can confidently report that installing and using docker engine on Ubuntu, at least, is quite trivial and clearly documented[0] on the website.
It also seems like Docker is now able to run rootless as well, so my nitpicks are actually more minor than I originally thought. It's still not daemonless, but it would work for my use case still I think.
Additionally, (and admittedly this isn't really Docker's fault), the default IP range for Docker's network happens to conflict with my employer's internal network, which is great fun to debug if you forget to change it.
I use CentOS, Ubuntu and Arch and have to regularly use third-party repos, PPAs or the AUR - this isn't a particularly uncommon thing to do when installing software. And it beats running a shell script, which is how k8s stuff works most of the time :P
My use case is the simplest of them all:
A docker compose file for postgres12 with a folder attached as permanent volume.
- colima couldnt do chmod, and it failed when i tried to restore database to folder. I tracked an issue on github, known stuff, issue is couple of years old.
- podman made it work somehow, data restore was under way - it run out of file descriptors, again - know bug with postgres and other scenarios, tracked on github for few years.
turned off, fired docker again, it works.
meh :(
I gave up on hibernation being a valid concept in the 1990's, there's too many things that can go wrong and computers are more complex today.I don't use hibernation and Docker has no issues.
I saw something on github the other day that may work (can’t remember the name, something about “box”), but it wasn’t available for Macos.
lxc launch ubuntu:22.04 docktest -c security.nest
More on https://bobcares.com/blog/lxd-and-docker-containers-nesting/
Btw, Sysbox is already supported in Docker-Desktop (business tier only), so you can easily do what you want with this instruction:
$ docker run -it --rm -e SYSBOX_SYSCONT_MODE=TRUE ghcr.io/nestybox/ubuntu-focal-systemd-docker:latest bash
Disclaimer: I'm Sysbox's co-creator and currently working for Docker.
But OP is looking for something that works for macos I believe.
Yes, the above instruction runs on macos too as long as you have docker-desktop installed.
https://github.com/kubernetes-sigs/kind/blob/main/images/bas...
You could run this as a standalone container
docker run --rm -d --name my-node --volume=/lib/modules:/lib/modules:ro --volume=/var --volume=/kind --privileged docker.io/kindest/node:v1.25.3
then exec in and use it like a vm. it comes with containerd installed and running but you could also install docker docker exec -it my-node bashhttps://blog.while-true-do.io/podman-systemd-in-containers/
Podman machine starts a VM that is just a Fedora distro, with systemd and you can create multiple instances. This way you can run these system containers easily.
I think you can run podman in podman. But your comment actually makes me wonder how easy it would be to run docker/podman in chroot
All you need to do for this is set the DOCKER_HOST variable. It gets slightly tricky with e.g. volume mounts of course. But otherwise this works fine. Including with docker-compose. The only other thing you need to do is some port forwarding from the vm; which you can do with ssh as well.
Podman, Colina, and other tools are essentially just nicer versions of this with a bit more features.
Edit: I’m using it for free.
If you’re happy with portainer and Docker I wouldn’t bother migrating.
It has a different aim, more of an admin view. I do use it regularly and would gladly take questions for the team. At some point we integrated this as a temporary solution for CRC to provide a container management view.
As an example https://www.tutorialworks.com/podman-monitoring-cockpit-fedo...
If you have suggestions to improve just let me know. I work closely with that team. And they gladly take feature requests or comments
Does that mean Podman is not technically ... rootless?
For example if you're using homebrew it will download the right specific file.
And universal is there so that people don't bother to know which arch is their computer.
Podman Desktop is planning also to bring a Kubernetes cluster very easily. For now you can deploy to an existing Kubernetes cluster the Pod (set of containers that Podman provides) and you can also switch your current context from the tray icon.
One day all of them will join XUL and MSHTML on a retirement home.
That seems pretty well packaged, honestly.
Since you mention, is the tarball not an option? This is supposed to be portable. What would you prefer?