503
Every time I use podman
(lemmy.nz)
Hint: :q!
Sister communities:
Community rules (click to expand)
1. Follow the site-wide rules
sudo in Windows.Please report posts and comments that break these rules!
Important: never execute code or follow advice that you don't understand or can't verify, especially here. The word of the day is credibility. This is a meme community -- even the most helpful comments might just be shitposts that can damage your system. Be aware, be smart, don't remove France.
Podman is unironically the better choice. Just try to make docker comply with your firewall...
Docker bypasses your firewall and runs as root. Only an idiot would allow that shit.... I'm an idiot. But I'm fixing that.
It doesn't "bypass your firewall"... it lets you shoot yourself in the foot. You're asking it to open ports without specifying an explicit network interface so it opens them on all interfaces. Which includes opening up the firewall, because what's the point of putting up a service and blocking it in the firewall.
Also, doing it by hand would be incredibly tedious. Docker automatically adjusts the rules to match the ports and interfaces to its private container netmasks, and brings them up or down as needed when the containers start/stop.
All you have to do is bind ports to localhost or to a private interface if you don't want the service to be publicly exposed.
Beginners get bitten by this because they say
ports: 9999:9999instead ofports: 127.0.0.1:9999:9999/tcplike they should. Unfortunately most examples out there use the terse version and never explain why it's bad.I like the idea of podman, but it’s just not stable. This meme was inspired by my frustration of trying to switch.
I literally did this yesterday and it wasn’t that hard. You just add
iptables:Falseto the docker config file.This + forwarding stuff to the docker namespace is working great for me. https://wiki.archlinux.org/title/Nftables#Working_with_Docker
Cult