Podman

Podman: Daemonless, Rootless Containers

Podman 47,580 (github.com/podman-container-tools/podman (https://github.com/podman-container-tools/podman 32,955 ), Apache-2.0, led by Red Hat) offers Docker 514 's command line without Docker's daemon. Each podman command is an ordinary process that forks a small monitor, conmon, per container and exits; the container is a child of conmon, not of a root-owned service. By default it runs rootless: containers live in your user namespace, with your UID mapped to root inside and a range from /etc/subuid for the other UIDs (User Namespaces). Upstream reached Podman 6.0 in June 2026; Ubuntu 26.04 225 's archive ships 5.7.0 with Buildah 1.42.1 919,369 , which is what runs here:

Installing Podman, and a container with no daemon behind itShell
sudo apt-get install -y -q podman buildah >/dev/null
podman --version
H='{{.Host.Security.Rootless}} {{.Host.OCIRuntime.Name}} {{.Host.RootlessNetworkCmd}}'
podman info -f "$H"
podman run -d --name l3-sleep docker.io/library/alpine:3 sleep 300 >/dev/null
P=$(podman inspect -f '{{.State.Pid}}' l3-sleep)
ps -o user,pid,ppid,comm -p $P -p $(ps -o ppid= -p $P)
echo "podman processes still running: $(pgrep -c podman)"
podman exec l3-sleep cat /proc/self/uid_map
podman rm -f -t 0 l3-sleep >/dev/null
podman run --rm postgres:18 true 2>&1 | cut -c 1-90
Output
podman version 5.7.0
true runc pasta
USER         PID    PPID COMMAND
dev       762610  762484 conmon
dev       762626  762610 sleep
podman processes still running: 0
         0       1000          1
         1     100000      65536
Error: short-name "postgres:18" did not resolve to an alias and no unqualified-search regi

The container's process belongs to dev, its parent is conmon, and no Podman process remains. Inside, UID 0 is your UID 1000 and UIDs 1 to 65536 map to 100000 and up, so "root" in the container has no power on the host. Networking comes from pasta (from the passt project), which relays packets in user space because an unprivileged user cannot create bridges. The last line is a Podman habit worth knowing: it refuses to guess a registry for a short image name unless an alias exists (alpine and node have one; postgres has not), which blocks the typosquatting trick of Typosquatting. Write fully qualified names such as docker.io/library/postgres:18.

Docker's client talks to a root daemon; Podman forks the container itself and exits
Docker's client talks to a root daemon; Podman forks the container itself and exits

Commands carry over one for one, and the podman-docker package even installs a docker alias. Podman's own image store, ~/.local/share/containers, is separate from Docker's.