Community
Chat Logs
Saturday, March 7, 2026
- phalethbye bye blue
- phalethwb blue, I'll deploy theanswerisc blog onto podman today, just to test the stability
- bluethx phaleth
- bluealright, so it's podman inside nspawn or vice versa or what?
- bluejust remember, I don't plan on using podman at all in the long run. per customer will be kvm, inside customer will be nspawn
- phalethoh, ok, sounds like I should do more reading of archwiki
- bluebasically the ideal is, we'll be having barebones, then we put kvm on it
- blueevery customer (=namespace) gets put in one kvm (or several, but it's only ever one customer per kvm)
- bluea barebones can have unlimited number of kvm spaces or whatever the term is
- bluekvm ensures proper separation
- bluewithin a kvm space, we use nspawn to separate all the machines
- blueso take dreamreal: if his user is dreamreal, he gets a kvm space. within that, he could have many repos, with many apps. all of them run within his space (or several spaces, depending on the size/number of apps)
- blueso he can never access the nspawn machines within another kvm space
- phalethok, but it could happen that if he deploys many apps to one kvm then one of them could get compromised and all the other apps could get hacked
- phalethwhy? cause nspawn containers run as root, that's why I'm messing around with rootless podman these days
- phalethI mean the isolation will prolly not be perfect, but any extra isolation is good
- phalethalso we will be able to use podman-compose, which is very very nice
- blueisn't there rootless nspawn?
- blueI think the limitation was creating networks, for that you need root privileges
- blueanyway podman is probably not great isolation either. if you really want perfect isolation we need kvm
- bluehow about one kvm per repo, will that be enough?
- blueI guess no, since if your test app is compromised someone could compromise your prod app
- phalethI'll just update the theanswerisc deployment today and so you can read it, for sure I'll try rootless nspawn too, but nspawn is such an underdocumented tech so I don't know, but I'll try
- bluecoo
- bluebtw phaleth, did you look into this? https://katacontainers.io/
- nevetKata Containers - Open Source Container Runtime Software
- bluedefinitely big red flag there that it's written in rust
- phalethyeah, noticed that several months ago, but didn't try that
- blueyou did try firecracker, right
- phalethnope, firecracker has memory issues, I'm willing to go with qemu/kvm
- bluefor that we'd need a dedi though
- blueI mean, it's likely our own vps runs in kvm
- phalethit does, contabo does not hide the fact they use qemu/kvm
- phalethfirecracker is also written in rust
- blueI think kvm should be enough, but obviously an overkill per app
- blueso the question becomes at what boundary level do you use it
- blueper customer, you said is too broad
- phalethI think nspawn and podman is a good solution, just need to avoid the use of root user like I do in all these mariadb containers
- bluebut why both?
- bluethey're competing products
- phalethcustomer -> project(s) -> machine(s) for builds/deployments... builds/deployments are linked together via one table as stack layers
- phalethcontainers within containers are done to gain more isolation, nothing is as perfect as a VM, but for containers there's non need for dedis
- phalethalso I think crun and pasta are really great, maybe later on we could consider podman within podman
- phalethboth rootless
- blueoki, I'll let you be the master of that
- blueas long as we fget proper security I don't really care how it's done
- phalethyeah, I'm not so inclined towards nspawn anymore cause of security, but I'll try if it can run rootless containers
- phalethalways assume the tech will be changing anyway, maybe katacontainers will win the game in few years
- blueya
- phalethrootless and also distroless are the buzzwords nowadays, also nspawn is heavily dependent on systemd which means the bottom layer of each container is huge and that will add up
- blueya
- bluephaleth: what about one dedi + several kvms (one per customer) + firecrackers inside kvm
- blueor is that still the memory issue
- phalethyeah, you can try fly again if you want to, the way they deal with OOMs related to firecracker is that they auto restart these microvms, no clue how they deploy postgres, prolly somehow differently
- phaleththe good think about nspawn container is that one can run anything on it
- bluemaybe we should just have a mixed security model, free customers share dedis, premiums are fully separated, get their own dedi + potentially kvm + nspawn
- bluethe ultimate security win is one dedi per customer, but it's also the most expensive
- phalethyeah, I think that's a good opportunity for marketing, having these shared vs. dedicated terms in the portfolio
- phalethalso not everybody will need dynamic apps with dbs behind them, if it's just a static site we can deploy it to a freebsd server where the only thing needed is a piece of nginx config
- phalethI mean there are already lots of services like that, but still
- blueua
- blueya
- phalethanother cool thing about podman is that it runs on freebsd, while nspawn is linux only
- blueI mean if you prefer podman, let's do it. I'm not sold on nspawn
- blueI just don't want to mix a thousand different technologies because in the end we need an abstraction API over them, we can't do it manually, and every one of them means the abstraction layer gets more complex
- bluedoes podman have a nice http-based API like docker?
- bluemaybe that solves our need to create an abstraction around calls to nspawn
- blueI wouldn't mind that, that would be great, would save me a lot of headache
- phalethyeah, I'd also like to use haproxy APIs
- phalethpodman does have docker compatible API https://medium.com/@pingkunga/how-to-enable-remote-api-in-podman-e32cede96309
- bluethat would be cool: in that case, the podman machien for repopack.com would use this API for management, that's amazing, no?
- blueI'm gonna try to install podman here locally and activate the API, so I can develop against it
- phalethyeah, it's great
- phalethI'd like to mess around with freebsd later on again, but now I'll be slowly introducing podman into the setup we already have
- blueok
- bluephaleth: I installed podman & ran a rootless container on it, lovely!
- phalethyeah, very simple
- bluepodman run -d --name hello-http --rm \ -p 127.0.0.1:8080:8080 \ docker.io/hashicorp/http-echo:latest \ -listen=:8080 -text="hello world"
- bluephaleth: ^ will start a new test container you can test with
- blue`podman stop hello-http` to kill it
- blueyou might need to remove the \
- blueit was a multiline command
- bluepodman run -d --name hello-http --rm -p 127.0.0.1:8080:8080 docker.io/hashicorp/http-echo:latest -listen=:8080 -text="hello world"
- blue^
- bluephaleth: systemctl --user enable --now podman.socket
- bluecheck that it worked: `systemctl --user status podman.socket --no-pager`
- blueshould say `Active: active (listening)`
- phalethon the vps?
- bluesure.. it'd be scoped to your user anyway, so no harm
- bluecurl --silent --unix-socket "$XDG_RUNTIME_DIR/podman/podman.sock" http://d/_ping
- blueshould say `OK`
- phalethyou can try this image ghcr.io/ammnt/freenginx:latest, it's a very hardened one
- bluealso try this
- bluecurl --silent --unix-socket "$XDG_RUNTIME_DIR/podman/podman.sock" http://d/v1.0.0/libpod/info | jq
- blue"version": {
- blue "APIVersion": "5.8.0",
- blue "GoVersion": "go1.26.0-X:nodwarf5",
- blue "Version": "5.8.0",
- blue "GitCommit": "07efc23e05c3d9aa15a0f30d57194737bfc4b6b1",
- blue "BuiltTime": "Sun Feb 22 22:45:50 2026",
- blue "Built": 1771796750,
- blue "OsArch": "linux/amd64",
- blue "Os": "linux"
- blue }
- blueit's written in go, hurrah!
- bluethis is amazing phaleth
- bluethis is exactly what we needed
- phalethyeah, only the crucial components to podman are written in C, crun and pasta
- bluephaleth: what'st he idea here? customer=user, podman runs in the context of the user?
- phalethyeah
- phalethI'd still do orgs already, but we said we will not do orgs
- blueyes, I meant orgs
- blueuser=org
- phalethorg can have multiple users
- blueyes but the podman would run under the org user?
- blueanywayt we can nail down the particulars later
- phalethyeah, for now just have orgs and users tables with 1:1 relationship
- phaleththis image works with podman docker.io/library/nginx:alpine-slim and it's only 5.46 MB
- bluecool
- bluephaleth: https://gitea.repopack.app/repopack/website
- bluecan you check if this works for you locally?
- blueclone repo & npm install & npx primate
- bluethis assumes you have podman running under your user
- phalethyeah, I'll try
- blueif all goes well, localhost:6161/networks should show networks, localhost:6161/containers should show containers
- blueif you don't have any containers running, just try the command earlier that creates an echo server
- phalethyou could add all that usage instructions into a README
- blueI could, but this will be fast changing. you won't see the networks or containers like that, directly anymore
- phalethI get Not Found error on both of those pages
- bluecurl --silent --unix-socket "$XDG_RUNTIME_DIR/podman/podman.sock" http://d/v5.8.0/libpod/containers/json | jq
- bluedoes this work? (Your version might be different)
- phalethnope, that curl call return nothing
- phalethI guess I was supposed to enable the API
- bluecurl --silent --unix-socket "$XDG_RUNTIME_DIR/podman/podman.sock" http://d/v1.0.0/libpod/info | jq
- bluewhat about this?
- blueyeah, I don't think your API is working
- blue14:08 < blue> phaleth: systemctl --user enable --now podman.socket
- blue14:08 < blue> check that it worked: `systemctl --user status podman.socket --no-pager`
- blue14:09 < blue> should say `Active: active (listening)`
- phalethyeah, you could add at least that to the README as that should not change
- phalethok, now I see the default network on the networks page
- phalethand no containers on the containers page since I just installed podman
- blueyes
- bluevery good
- phalethyeah, but not very self explorable
- blueyes
- blueI'm experimenting as we speak, so I haven't got to document much yet
- bluethe main question is if it reliably works for you, on another machine
- blueand we answered it now
- phalethyup
- phalethnotice the shell changing here https://images4.imagebam.com/da/99/f3/ME1B56O7_o.png
- phalethroot -> non-root -> root -> non-root
- blueyes