Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Docker is already on an informal ban list when it come to US government container deployments in higher classification environments. Most of those situations require Podman based solutions.


This is also related to the Client Server model supported by Docker versus the Fork/Exec Model supported by Podman.

Podman works closely with the HPC (High Performance Computing) world. Checkout the article about how the fastest computers in the world in the most secure facilities in the world are using Podman.

https://www.nersc.gov/assets/Uploads/06-Containers-for-HPC-S...

https://opensource.com/article/23/1/hpc-containers-scale-usi...


But docker can also run rootless for almost as long as podman has existed. Why would it still be on such a blacklist?


Because by default it does not, and default matter (a lot!).

Also license and cost aspects.

Like ask 100 devs which have Linux and Docker, I would be surprised if more then 10 made sure that docker _can only run_ without root rights (and there are two ways to do so with different complexity and consequences).


Not so much a blacklist as just a cost saving measure, as the other advantage Podman has is you don’t have to pay the Mirantis bill, both in terms of money and IT overhead.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: