503
submitted 2 days ago* (last edited 1 day ago) by WolfLink@sh.itjust.works to c/linuxmemes@lemmy.world

EDIT: For some context, I recently gave podman another go. I have a few services on my homelab server set up in docker containers, so I tried migrating to podman.

After the second major bug (open issue on github) I encountered looked like it would require completely dropping using compose files to work around, I gave up and went back to docker.

I like the idea of podman, but it’s just not stable. I’ll try again in a year or so.

As a bonus, docker’s CLI is significantly nicer.

you are viewing a single comment's thread
view the rest of the comments
[-] lian_drake@lemmy.world 36 points 1 day ago

Podman is unironically the better choice. Just try to make docker comply with your firewall...

[-] altphoto@lemmy.today 14 points 1 day ago

Docker bypasses your firewall and runs as root. Only an idiot would allow that shit.... I'm an idiot. But I'm fixing that.

[-] lemmyvore@feddit.nl 2 points 1 day ago

It doesn't "bypass your firewall"... it lets you shoot yourself in the foot. You're asking it to open ports without specifying an explicit network interface so it opens them on all interfaces. Which includes opening up the firewall, because what's the point of putting up a service and blocking it in the firewall.

Also, doing it by hand would be incredibly tedious. Docker automatically adjusts the rules to match the ports and interfaces to its private container netmasks, and brings them up or down as needed when the containers start/stop.

All you have to do is bind ports to localhost or to a private interface if you don't want the service to be publicly exposed.

Beginners get bitten by this because they say ports: 9999:9999 instead of ports: 127.0.0.1:9999:9999/tcp like they should. Unfortunately most examples out there use the terse version and never explain why it's bad.

[-] WolfLink@sh.itjust.works 1 points 1 day ago

Podman is unironically the better choice.

I like the idea of podman, but it’s just not stable. This meme was inspired by my frustration of trying to switch.

Just try to make docker comply with your firewall.

I literally did this yesterday and it wasn’t that hard. You just add iptables:False to the docker config file.

[-] unlit3487@lemmy.world 1 points 1 day ago

This + forwarding stuff to the docker namespace is working great for me. https://wiki.archlinux.org/title/Nftables#Working_with_Docker

this post was submitted on 24 Aug 2026
503 points (93.3% liked)

linuxmemes

32597 readers
2515 users here now

Hint: :q!


Sister communities:


Community rules (click to expand)

1. Follow the site-wide rules

2. Be civil
  • Understand the difference between a joke and an insult.
  • Do not harrass or attack users for any reason. This includes using blanket terms, like "every user of thing".
  • Don't get baited into back-and-forth insults. We are not animals.
  • Leave remarks of "peasantry" to the PCMR community. If you dislike an OS/service/application, attack the thing you dislike, not the individuals who use it. Some people may not have a choice.
  • Bigotry of any kind will not be tolerated. This is an LGBTQ+-friendly community -- if that is a problem for you, you should leave.
  • 3. Post Linux-related content
  • Including Unix and BSD.
  • Non-Linux content is acceptable as long as it makes a reference to Linux. For example, the poorly made mockery of sudo in Windows.
  • No porn, no politics, no trolling or ragebaiting.
  • Don't come looking for advice, this is not the right community.
  • 4. No recent reposts
  • Everybody uses Arch btw, can't quit Vim, <loves / tolerates / hates> systemd, and wants to interject for a moment. You can stop now.
  • 5. 🇬🇧 Language/язык/Sprache
  • This is primarily an English-speaking community. 🇬🇧🇦🇺🇺🇸
  • Comments written in other languages are allowed.
  • The substance of a post should be comprehensible for people who only speak English.
  • Titles and post bodies written in other languages will be allowed, but only as long as the above rule is observed.
  • 6. (NEW!) Regarding public figuresWe all have our opinions, and certain public figures can be divisive. Keep in mind that this is a community for memes and light-hearted fun, not for airing grievances or leveling accusations.
  • Keep discussions polite and free of disparagement.
  • We are never in possession of all of the facts. Defamatory comments will not be tolerated.
  • Discussions that get too heated will be locked and offending comments removed.
  •  

    Please report posts and comments that break these rules!


    Important: never execute code or follow advice that you don't understand or can't verify, especially here. The word of the day is credibility. This is a meme community -- even the most helpful comments might just be shitposts that can damage your system. Be aware, be smart, don't remove France.

    founded 3 years ago
    MODERATORS