Urgent.News

What's breaking now, across thousands of outlets.

Tech

Using docker-compose with Podman rootless

Podman, a Docker alternative for Linux, can operate without root privileges. It can communicate with the Docker API via a UNIX-domain socket, enabling its use with various Docker ecosystem tools such as docker-compose. Podman utilizes Linux user namespaces, mapping the root user inside containers to the host user and adjusting other UIDs and GIDs according to /etc/subuid and /etc/subgid. This guide assumes Podman and docker-compose are pre-installed, typically via the Linux distribution's package manager.

To activate and initiate the Podman socket, execute the command in your user account (not as root): this creates a UNIX-domain socket at ${XDG_RUNTIME_DIR}/podman/podman.sock. ${XDG_RUNTIME_DIR} is a private tmpfs temporary file system unique to each user. Please note, this command requires a systemd session. If running as another user, avoid using sudo as it doesn't establish a systemd session.

Instead, utilize machinectl shell --uid=your-username from the systemd-container package, log in as your user on a TTY or via SSH, or employ tools like machinectl shell.

Set the DOCKER_HOST environment variable to point to the Podman socket for tools like docker-compose to function correctly. Add the line to your shell configuration (e.g., ~/.zshrc for Zsh) to ensure this setting persists. Depending on your Linux distribution, docker-compose may also be accessible as docker compose, but its usage remains consistent. An alias can be created in your shell for convenience.

If Docker is installed but not uninstalled, halt and disable its systemd service (as root) to avoid any impact on existing Docker data. Should you decide to revert, these commands won't delete Docker data. Instead, you can relaunch it (as root) with the appropriate command.

The podman command mirrors the functionality of docker, but you can continue using docker if preferred. It recognizes the DOCKER_HOST variable and can communicate with the Podman socket similarly to docker-compose. To assume root privileges without initiating a container, utilize podman unshare, which launches a new shell as root within a user namespace, akin to sudo -i.

This allows manipulation of files owned by container users (e.g., chown, chmod). To access the contents of a running container, employ podman mount. After executing podman unshare, navigate to the path displayed by podman mount container-name-or-id. You can then edit files using your preferred text editor within the container. For rootless Docker, refer to their documentation.

Once installed and running, set the DOCKER_HOST environment variable accordingly. Please note, rootless Docker lacks the equivalent of podman unshare and podman mount, though similar outcomes can be achieved with unshare and nsenter. By default, Podman containers terminate upon the closure of your user's last systemd session. To maintain them after logout, enable user lingering for your user account (as root).

Written by urgent.news from Lobsters's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at elou.world →

More in Tech

More from Monday 5 October →