podman-rootful-network
conmon
podman-rootful-network | conmon | |
---|---|---|
1 | 4 | |
15 | 401 | |
- | 3.0% | |
5.0 | 7.7 | |
2 months ago | 5 days ago | |
Python | C | |
BSD 2-clause "Simplified" License | Apache License 2.0 |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
podman-rootful-network
-
Which alternative for slirp4netns in rootless containers is better?
Do you mean for example this project? https://github.com/neverpanic/podman-rootful-network
conmon
-
Creating Kubernetes Cluster With CRI-O
It is an open-source, community-driven project which supports OCI-based container registries. It is being maintained by contributors working in Red Hat, Intel, etc. It also comes with a monitoring program known as conmon. Conmon is an OCI container runtime monitor, which makes the communication between CRI-O and runc for a single container.
-
Which alternative for slirp4netns in rootless containers is better?
When considering using socket activation it's good to know that socket-activation has the advantage that you can create on-demand services. And in the future you might be able to do container image upgrades without loosing an active TCP connection https://github.com/containers/conmon/issues/393 (Right now it's just a feature request that I wrote).
-
Docker is dead?!? Podman - an alternative tool?
This was a wrong assumption. Podman directly uses runC or crun instead of containerd using a technology named conmon. Some more useful information can be found in this article.
-
Podman: A Daemonless Container Engine
Well, "daemonless" is kind of marketing - there is still this daemon-per-container 'conmon' thing https://github.com/containers/conmon and I don't get why it is needed because 1) who actually needs to re-attach anyway? 2) container's streams are already properly handled by whatever supervisor (e.g. systemd). You can't disable conmon and I'm not sure if its usage is not hardcoded throughout the codebase.
I would very much like to use Podman as a finally proper container launcher in production (non-FAANG scale - at which you maybe start to need k8s), but having an unnecessary daemon moving part in thousands lines of C makes me frown so far.
What are some alternatives?
podman-nginx-socket-activation - Demo of how to run socket-activated nginx with Podman
podman - Podman: A tool for managing OCI containers and pods.
podman-networking-docs - rootless Podman networking documentation with examples
runc - CLI tool for spawning and running containers according to the OCI specification
systemd - The systemd System and Service Manager
crun - A fast and lightweight fully featured OCI runtime and C library for running containers
docker - Docker - the open-source application container engine
distribution-spec - OCI Distribution Specification
go - The Go programming language
hub-feedback - Feedback and bug reports for the Docker Hub
pq - a command-line Protobuf parser with Kafka support and JSON output
k3d - Little helper to run CNCF's k3s in Docker