Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Daniel Walsh

Rating No ratings yet

The next generation of containers is here. Learn Podman directly from its creator, discover its exceptional security features, and start managing rootless containers that integrate easily into your systems. In Podman in Action you will learn how to: - Build and run containers in rootless mode - Develop and manage pods - Use SystemD to oversee a container’s lifecycle - Work with the Podman service via Python - Keep your containers confined using Podman security features - Manage containerized applications on edge devices Podman in Action shows you how to deploy containerized applications on Linux, Windows, and MacOS systems using Podman. Written by Daniel Walsh, who leads the Red Hat Podman team, this book teaches you how to securely manage the entire application lifecycle without human intervention. You’ll quickly get to grips with Podman’s unique advantages over Docker, and learn how easy it is to migrate your Docker-based infrastructure. It also demonstrates how, with Podman, you can easily convert containerized applications into Kubernetes-based microservices.

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
# Podman in Action: Secure, Rootless Containers for Kubernetes, Microservices, and More ## 【One-Line Pitch】 A practical, author-led guide to mastering Podman—the daemonless, rootless container engine—covering everything from basic commands to advanced security, with clear paths for migrating from Docker and integrating with Kubernetes. Essential reading for DevOps engineers, system administrators, and developers who want secure, production-ready container workflows without the Docker daemon's overhead. ## 【Book Arc】 - **Opening (~0%–10%)**: Introduces Podman as the "next generation" container engine, contrasting its fork/exec model with Docker's client-server architecture, and explains core container concepts including image formats (rootfs, JSON config, manifest lists) and advanced Linux security features like capabilities and SELinux. - **Early (~10%–23%)**: Dives into hands-on command-line work—running containers with `podman run`, understanding image pulling mechanics, interactive terminal options, and the full container lifecycle (start, stop, exec, commit). - **Early–Middle (~23%–39%)**: Covers image management comprehensively: inspecting images with `podman image inspect`, tagging, pushing to registries (like quay.io), pulling images, and removing images—including handling "dangling images" and dependency-aware removal. - **Middle (~39%–48%)**: Explores building images using Containerfiles/Dockerfiles, explaining the FROM directive, scratch builds, and the full `podman build` workflow, plus a complete reference of image-related subcommands (pull, push, save, load, sign, trust, tree, etc.). - **Middle–Late (~48%–70%)**: Moves into volumes and persistent storage, pod management, and systemd integration for container lifecycle oversight—the operational heart of running containers in production. - **Late (~70%–100%)**: Focuses on security in depth: SELinux type enforcement, Multi-Category Security separation, seccomp system call isolation, VM-based isolation, secret handling, image trust/signing, and the daemonless model's security advantages. Appendices cover OCI runtimes, installation, and macOS/Windows specifics. ## 【Key Takeaways】 - **Podman's fork/exec model eliminates the daemon** (Early): Unlike Docker's client-server architecture with its privileged daemon socket, Podman launches containers as child processes of the user's shell—reducing attack surface and enabling rootless operation. This is the foundational architectural difference that drives the book's security narrative. - **Rootless containers are the default, not an afterthought** (Opening): Podman was designed from the ground up for rootless operation, meaning users can run containers without root privileges, dramatically improving security for multi-tenant and development environments. - **The CLI is Docker-compatible by design** (Middle): Podman's command structure mirrors Docker exactly, so `alias docker=podman` works for most workflows—making migration trivial while adding extra commands like `podman image mount` for advanced use cases. - **Container images are three-part structures** (Early): Understanding the rootfs directory tree, the JSON config (with environment variables, commands, labels), and the manifest list (for multi-architecture support) is essential for debugging and optimizing images. - **Volumes with SELinux labels require care** (Middle): The `:z` and `:ro,z` options in volume mounts handle SELinux relabeling—a critical detail for running containers on RHEL/Fedora systems that often trips up Docker veterans. - **Systemd integration enables production lifecycle management** (Middle): Using systemd units to oversee container lifecycles provides automatic restart, logging, and dependency management—the book's approach to "human intervention-free" operations. - **Security is layered, not single-point** (Late): Podman simultaneously uses Linux capabilities, SELinux, seccomp, and optional VM isolation (via Kata or gVisor), with the daemonless model adding auditing and logging advantages over Docker's socket-based approach. ## 【Reading Tips】 - **Skim the first chapter's security overview** if you're already familiar with container basics—the table of Linux security features (capabilities, SELinux) is reference material you can return to later. - **Deep-read Chapter 2's command walkthroughs** with a terminal open; the `podman run`, `commit`, and `inspect` examples are best learned by doing, not just reading. - **Pay special attention to the Containerfile/Dockerfile section** (around 42%–48%)—the FROM scratch pattern and layer-caching behavior are practical skills you'll use daily. - **The security chapters (10–11) reward careful reading** but can be skimmed first and revisited when you encounter specific production issues like SELinux denials or image trust problems. - **Use the appendices strategically**: Appendix C (installation) and E/F (macOS/Windows) are practical references to consult when setting up your environment, not continuous reading material. ## 【Coverage Limits】 This guide synthesizes the book's core container management, image building, and security content. The excerpts do not cover the book's detailed treatment of Kubernetes integration, Python API usage, or edge device deployment scenarios in depth—these sections exist in the full book but were not included in the source material. ##
Page 12
ntainers? 230 appendix A Podman-related container tools 232 appendix B OCI runtimes 246 appendix C Getting Podman 254 appendix D Contributing to Podman 259 a...
View in text
Excerpt 2
t Linux kernel Figure 1.8 Docker client-server architecture. The container is a direct descendant of containerd, not the Docker client. The kernel sees no r...
View in text
Excerpt 3
ly want to examine the configuration information associated with an image by inspecting it. 2.2.3 Inspecting images In the previous sections, I mentioned a c...
View in text
Excerpt 4
an existing image. For example, FROM registry.access.redhat.com/ubi8 causes Podman to pull the ubi8 image from the registry.access.redhat.com container regis...
View in text
Excerpt 5
location of container storage graphroot = "/var/mystorage" Execute podman info to see if the change took place: $ sudo podman info … Store: configFile: /etc...
View in text
Excerpt 6
h container volumes and discussed ways you can handle them. Reentering the user namespace, you can remove the file: $ podman unshare rm -rf test Hopefully, y...
View in text
Excerpt 7
tion tells Podman to roll back to the previous image if the update fails, as covered in the next section. SYSTEMD TIMERS TRIGGER PODMAN UPDATES Podman ships ...
View in text
Excerpt 8
create a mysystemd directory and place the Containerfile in the directory: $ mkdir mysystemd $ mv Containerfile mysystemd/ You can now run podman play kube -...
View in text
Tags
AI categories
Cloud NativeDevOps容器安全
ISBN: 1633439682
Publish Year: 2023
Language: English
Pages: 312
File Format: PDF
File Size: 13.9 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…