I recently converted a team project over to Podman. I only had an issue with one container running rootless. Redirecting port 80 to a non-privileged port solved the issue. What are you seeing?
My eventual goal for this image is to deploy it in a Kubernetes cluster. As you can tell I'm just starting this process, but I want to be mindful of how I can keep my container secure as it runs on shared resources.
How do you handle binding to privileged ports with rootless Podman? That's what stopped me from deploying via Podman the last time I tried.
I didn't. We run reverse proxies in front of our apps anyway so I just changed the port at the proxy. I wish I had a better answer for you. Maybe someone else does.
Set `sudo sysctl -w net.ipv4.ip_unprivileged_port_start=80`
I'm using a firewalld rich rule to forward host 443 to 8443, then the proxy container has 8443:8443 mapped. Works perfectly. All on Fedora but other firewalls should be able to do the same.