Podman 4.4
github.com
github.com
So the following works:
[sam@isis ~]$ podman network create foo
foo
[sam@isis ~]$ podman run -d --name=host1 --network=foo --init registry.access.redhat.com/ubi9/ubi-minimal sleep inf
1f7ffa0e474f7116d782ffa4d8dd9c0454893e9dac54b2cd9e61481a7f86a2ff
[sam@isis ~]$ podman run -d --name=host2 --network=foo --init registry.access.redhat.com/ubi9/ubi-minimal sleep inf
d8ffa58cb9de77305545b9f85043c016d03193adb6543b1768a68623b044b0e5
[sam@isis ~]$ podman exec host1 getent ahosts host2
10.89.0.3 STREAM host2.dns.podman
10.89.0.3 DGRAM
10.89.0.3 RAW
[sam@isis ~]$ podman exec host2 getent ahosts host1
10.89.0.2 STREAM host1.dns.podman
10.89.0.2 DGRAM
10.89.0.2 RAW
i.e., we have a network called 'foo' to which containers 'host1' and 'host2' are attached; they can resolve each others hostnames.It's worth noting if you are trying this on a system where you previously ran podman <= 3, I think you have to 'podman system reset' to get a new configuration with the new Podman 4 network implementation.
(Personally I just run all containers with --host=net, this is just for local development, who cares)
I think this will work with docker-compose as long as you 'systemctl --user start podman.socket' and 'export DOCKER_HOST=unix:/$XDG_RUNTIME_DIR/podman/podman.sock'.
apt install containernetworking-plugins podman-plugins
Once I get everything built the way I want I dump the config to a yaml with “podman generate kube” for future reference.
It’s also nice being able to use systemd service files to start/stop everything, and podman has a command to generate those too.
If you already have sudo/root access for your user, rootless is just going to cause more problems.
Frist, you can run the container with --cap-add=net_bind_service which allows processes to bind to privileged ports:
$ podman run --cap-add=net_bind_service --rm -it --user=1 localhost/socat
bash-5.1$ id
uid=1(bin) gid=1(bin) groups=1(bin)
bash-5.1$ capsh --print
Current: cap_net_bind_service=eip
Bounding set =cap_chown,cap_dac_override,cap_fowner,cap_fsetid,cap_kill,cap_setgid,cap_setuid,cap_setpcap,cap_net_bind_service,cap_sys_chroot,cap_setfcap
Ambient set =cap_net_bind_service
Current IAB: !cap_dac_read_search,!cap_linux_immutable,^cap_net_bind_service,!cap_net_broadcast,!cap_net_admin,!cap_net_raw,!cap_ipc_lock,!cap_ipc_owner,!cap_sys_module,!cap_sys_rawio,!cap_sys_ptrace,!cap_sys_pacct,!cap_sys_admin,!cap_sys_boot,!cap_sys_nice,!cap_sys_resource,!cap_sys_time,!cap_sys_tty_config,!cap_mknod,!cap_lease,!cap_audit_write,!cap_audit_control,!cap_mac_override,!cap_mac_admin,!cap_syslog,!cap_wake_alarm,!cap_block_suspend,!cap_audit_read,!cap_perfmon,!cap_bpf,!cap_checkpoint_restore
Securebits: 00/0x0/1'b0 (no-new-privs=0)
secure-noroot: no (unlocked)
secure-no-suid-fixup: no (unlocked)
secure-keep-caps: no (unlocked)
secure-no-ambient-raise: no (unlocked)
uid=1(bin) euid=1(bin)
gid=1(bin)
groups=1(bin)
Guessed mode: UNCERTAIN (0)
bash-5.1$ socat -dd - TCP-LISTEN:22
2023/02/21 09:19:34 socat[82] N reading from and writing to stdio
2023/02/21 09:19:34 socat[82] W ioctl(5, IOCTL_VM_SOCKETS_GET_LOCAL_CID, ...): Inappropriate ioctl for device
2023/02/21 09:19:34 socat[82] N listening on AF=2 0.0.0.0:22
Second, you can run the container with --sysctl=net.ipv4.ip_unprivileged_port_start=0 which tells the kernel to allow any process to bind to ports above 0 instead of the default of 1024: $ podman run --sysctl=net.ipv4.ip_unprivileged_port_start=0 --rm -it --user=1 registry.access.redhat.com/ubi9/ubi-minimal
bash-5.1$ id
uid=1(bin) gid=1(bin) groups=1(bin)
bash-5.1$ socat -dd - TCP-LISTEN:22
2023/02/21 09:26:55 socat[59] N reading from and writing to stdio
2023/02/21 09:26:55 socat[59] W ioctl(5, IOCTL_VM_SOCKETS_GET_LOCAL_CID, ...): Inappropriate ioctl for device
2023/02/21 09:26:55 socat[59] N listening on AF=2 0.0.0.0:22As in -- on a multi-user machine, this could be a problem.
Podman added an optional rootful daemon a few releases ago that you can run in place of/next to the docker daemon that (theoretically) supports all the same docker network functionality specifcally so docker and docker compose commands can be run unchanged on podman.
Most repos I check out still have only docker specific commands…
Even though most things are similar, the differences in e.g networking (for example host.docker.internal vs host.containers.internal) create lots of Issues for me
I think I used something called buildah to package something, and it had some parameter for a name, but then trying to run it using podman, podman didn't seem to have any way to reference the container image that I THINK buildah created. I think there was also something called spokeo but I don't recall what it did, or it did not help this workflow.
The tutorials all seemed to assume pulling images from the internet.
Anyone have a good podman tutorial that really goes from install podman -> make container -> run container on a Linux box?
$ sudo apt install podman buildah
$ mkdir empty && cd empty
$ cat > Containerfile <<EOF
FROM alpine:3.14
RUN echo 'echo hello podman!' > /root/hello.sh
ENTRYPOINT ["/bin/sh", "/root/hello.sh"]
EOF
$ buildah build -f Containerfile -t hello-podman .
$ podman run -it --rm localhost/hello-podman:latest
hello podman!
edit: stryan has more minimalist instructions above.I will now bitch about how everything needs to be converted to some obscure url or pseudo-url when a file path would do. This has bitten me on:
- JSP tag libraries
- XML xsd references (which back in the Spring XML namespace-go-nuts era was really annoying)
- file:///fully/qualified/path
There, I have bitched.
podman build -t what_the_image_to_be_tagged .
Then to reference the container by name when you run it, you gotta specify that at runtime:
podman run --name foo the_image_you_just_tagged
The version in official Ubuntu apt repo is still 3.x ..
Or maybe you can request it via the process outlined at https://wiki.ubuntu.com/SyncRequestProcess?
Ubuntu's podman 3.4 was pulled from Debian Unstable at some point (Debian Stable is still on 3.0?). It looks like Debian Testing has 4.3, so they're probably waiting to just use that from Debian Stable in Ubuntu Lunar rather than the community maintaining their own version.