
Podman
- 106 installs
- 44 repo stars
- Updated May 22, 2026
- bagelhole/devops-security-agent-skills
Podman is a Claude Code skill for running and managing rootless, daemonless containers and Kubernetes-style pods with Docker-compatible commands.
About
Podman is a skill for running and managing containers without a daemon using its rootless container engine. A developer uses it to run Docker-compatible commands, create Kubernetes-style pods, integrate with systemd via generated units or Quadlet, and manage images, networks, volumes, and registries. It suits security-conscious environments and systems without Docker.
- Daemonless, rootless container engine with Docker-compatible commands
- Kubernetes-style pods, systemd integration, and Quadlet units
- Compose compatibility and native kube play from Kubernetes YAML
Podman by the numbers
- 106 all-time installs (skills.sh)
- Ranked #536 of 1,435 DevOps & CI/CD skills by installs in the Skillselion catalog
- Data as of Jul 28, 2026 (Skillselion catalog sync)
podman capabilities & compatibility
- Capabilities
- container hardening · devops · kubernetes hardening
- Works with
- docker · kubernetes
- Use cases
- devops
- Platforms
- Linux
What podman says it does
Run and manage containers without a daemon using Podman's rootless container engine.
Rootless cannot bind to ports < 1024 by default
Generate Kubernetes YAML from pod
npx skills add https://github.com/bagelhole/devops-security-agent-skills --skill podmanAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 106 |
|---|---|
| repo stars | ★ 44 |
| Last updated | May 22, 2026 |
| Repository | bagelhole/devops-security-agent-skills ↗ |
What it does
Run and manage rootless, daemonless containers and pods with Podman and Docker-compatible commands.
Who is it for?
Developers running containers without root, without Docker, or in security-conscious environments.
When should I use this skill?
When running containers without root privileges or managing containers on systems without Docker.
What you get
Containers and pods running rootless under Podman with systemd or Quadlet integration.
- Rootless containers and pods
- systemd or Quadlet unit files
- Compose or kube-play deployments
By the numbers
- 5-row Docker vs Podman comparison table
- Requires Podman 4.x+
Files
Podman
Run and manage containers without a daemon using Podman's rootless container engine.
When to Use This Skill
Use this skill when:
- Running containers without root privileges
- Managing containers on systems without Docker
- Creating pod-based container groups
- Using systemd for container management
- Working in security-conscious environments
Prerequisites
- Podman installed (4.x+)
- For rootless: user namespaces enabled
- Basic container concepts understanding
Key Differences from Docker
| Feature | Docker | Podman |
|---|---|---|
| Architecture | Client-daemon | Daemonless |
| Root required | Default | Optional (rootless) |
| Pod support | No | Yes (Kubernetes-style) |
| Systemd integration | Limited | Native |
| Socket | docker.sock | podman.sock (optional) |
Basic Commands
Container Operations
# Run container (identical to Docker)
podman run -d --name webserver -p 8080:80 nginx
# List containers
podman ps -a
# Stop and remove
podman stop webserver
podman rm webserver
# Execute command
podman exec -it webserver /bin/sh
# View logs
podman logs -f webserverImage Management
# Pull image
podman pull docker.io/library/nginx:latest
# List images
podman images
# Build image
podman build -t myapp:latest .
# Push to registry
podman push myapp:latest registry.example.com/myapp:latest
# Remove image
podman rmi nginx:latestRootless Containers
Setup
# Check user namespace support
cat /proc/sys/user/max_user_namespaces
# Enable if needed (as root)
echo "user.max_user_namespaces=28633" | sudo tee /etc/sysctl.d/userns.conf
sudo sysctl -p /etc/sysctl.d/userns.conf
# Configure subuid/subgid for user
sudo usermod --add-subuids 100000-165535 --add-subgids 100000-165535 $USER
# Verify
podman unshare cat /proc/self/uid_mapRunning Rootless
# Run as regular user (no sudo)
podman run -d --name myapp -p 8080:80 nginx
# Check user namespace mapping
podman unshare id
# Verify non-root
podman top myapp userPort Considerations
# Rootless cannot bind to ports < 1024 by default
# Use ports >= 1024
podman run -d -p 8080:80 nginx
# Or enable unprivileged ports (as root)
echo "net.ipv4.ip_unprivileged_port_start=80" | sudo tee /etc/sysctl.d/ports.conf
sudo sysctl -p /etc/sysctl.d/ports.confPods
Creating Pods
# Create pod
podman pod create --name mypod -p 8080:80 -p 5432:5432
# Add containers to pod
podman run -d --pod mypod --name web nginx
podman run -d --pod mypod --name db postgres:15
# List pods
podman pod ps
# Containers share network namespace
podman exec web curl localhost:5432Pod Management
# Start/stop pod (affects all containers)
podman pod start mypod
podman pod stop mypod
# Remove pod and containers
podman pod rm -f mypod
# View pod details
podman pod inspect mypod
# Generate Kubernetes YAML from pod
podman generate kube mypod > mypod.yamlSystemd Integration
Generate Systemd Unit
# Generate unit file for container
podman generate systemd --new --name myapp > ~/.config/systemd/user/container-myapp.service
# For pod
podman generate systemd --new --name mypod --files
# Reload systemd
systemctl --user daemon-reload
# Enable and start
systemctl --user enable --now container-myapp.serviceQuadlet (Podman 4.4+)
# ~/.config/containers/systemd/webapp.container
[Container]
Image=docker.io/library/nginx:latest
PublishPort=8080:80
Volume=webapp-data:/usr/share/nginx/html
[Service]
Restart=always
[Install]
WantedBy=default.target# Reload to generate service
systemctl --user daemon-reload
# Start the service
systemctl --user start webappCompose Compatibility
Using Podman Compose
# Install podman-compose
pip install podman-compose
# Run compose file
podman-compose up -d
# Or use Docker Compose with Podman socket
systemctl --user enable --now podman.socket
export DOCKER_HOST=unix:///run/user/$UID/podman/podman.sock
docker-compose up -dNative Podman Kube
# Play Kubernetes YAML
podman kube play deployment.yaml
# Stop and remove
podman kube down deployment.yamlNetworking
Network Management
# Create network
podman network create mynetwork
# Run on network
podman run -d --network mynetwork --name app myapp
# Connect container to network
podman network connect mynetwork existing-container
# List networks
podman network ls
# Inspect network
podman network inspect mynetworkDNS Resolution
# Containers on same network can resolve by name
podman run -d --network mynetwork --name db postgres:15
podman run -d --network mynetwork --name app \
-e DATABASE_HOST=db myappStorage
Volume Management
# Create volume
podman volume create mydata
# Use volume
podman run -d -v mydata:/data myapp
# List volumes
podman volume ls
# Inspect volume
podman volume inspect mydata
# Rootless volumes location
ls ~/.local/share/containers/storage/volumes/Bind Mounts
# Bind mount with SELinux label
podman run -v ./data:/app/data:Z myapp
# Z = private label (single container)
# z = shared label (multiple containers)Registry Configuration
Configure Registries
# Edit registries.conf
# ~/.config/containers/registries.confunqualified-search-registries = ["docker.io", "quay.io"]
[[registry]]
prefix = "docker.io"
location = "docker.io"
[[registry.mirror]]
location = "mirror.gcr.io"Authentication
# Login to registry
podman login docker.io
# Login to private registry
podman login registry.example.com
# Credentials stored in
# ~/.config/containers/auth.jsonBuilding Images
Buildah Integration
# Podman uses Buildah for builds
podman build -t myapp:latest .
# Build with specific format
podman build --format docker -t myapp .
# Multi-stage build
podman build --target production -t myapp:prod .Buildah Commands
# Create container from scratch
buildah from scratch
buildah copy working-container ./app /app
buildah config --entrypoint '["/app/main"]' working-container
buildah commit working-container myapp:minimalCommon Issues
Issue: Permission Denied
Problem: Cannot access files in mounted volumes Solution: Use :Z or :z suffix for SELinux, or check ownership
Issue: Cannot Connect to Container
Problem: Port not accessible in rootless mode Solution: Use ports >= 1024 or configure unprivileged port start
Issue: Slow Image Pulls
Problem: Images download slowly Solution: Configure registry mirrors in registries.conf
Issue: Systemd Service Fails
Problem: Container doesn't start via systemd Solution: Enable lingering: loginctl enable-linger $USER
Best Practices
- Use rootless mode for enhanced security
- Leverage pods for related containers
- Generate systemd units for production
- Use Quadlet for declarative container services
- Configure SELinux labels for bind mounts
- Enable user lingering for persistent services
- Use podman auto-update for automatic updates
- Alias
dockertopodmanfor compatibility
Related Skills
- docker-management - Docker fundamentals
- kubernetes-ops - K8s orchestration
- container-hardening - Security