CHEAT SHEET
Podman cheat sheet
Run, inspect and build containers with Podman, then turn them into systemd services with Quadlet.
Images
podman pull registry.access.redhat.com/ubi9/ubi # download an imagepodman images # list local imagespodman rmi IMAGE # remove an imagepodman login registry.redhat.io # sign in to a registryskopeo inspect docker://registry.access.redhat.com/ubi9/ubi # look without pulling
Running containers
podman run -it --rm registry.access.redhat.com/ubi9/ubi bash # throwaway shellpodman run -d --name web -p 8080:8080 registry.access.redhat.com/ubi9/httpd-24podman run -e KEY=value IMAGE # an environment variablepodman run -v /data:/data:Z IMAGE # a volume (:Z fixes the SELinux label)podman ps # running containerspodman ps -a # including stopped ones
Managing containers
podman logs -f web # follow the logspodman exec -it web bash # a shell inside a running containerpodman stop web # stop itpodman start web # start it againpodman restart web # restart itpodman rm web # remove itpodman inspect web # full details as JSONpodman port web # published portspodman system prune # remove unused data
Building images
FROM registry.access.redhat.com/ubi9/ubiRUN dnf -y install httpd && dnf clean allCOPY index.html /var/www/html/EXPOSE 80CMD ["httpd", "-DFOREGROUND"]
podman build -t web:1.0 . # build from the Containerfile in this folderpodman tag web:1.0 registry.example.com/web:1.0podman push registry.example.com/web:1.0
Quadlet: containers as systemd services
# ~/.config/containers/systemd/web.container (rootful: /etc/containers/systemd/)[Unit]Description=Web container[Container]Image=registry.access.redhat.com/ubi9/httpd-24PublishPort=8080:8080[Install]WantedBy=default.target
systemctl --user daemon-reload # generate web.service from web.containersystemctl --user start web.service # start itsystemctl --user status web.service # check itloginctl enable-linger alice # keep user services running after logout
Volumes and networks
podman volume create data # a named volumepodman volume ls # list volumespodman network ls # list networkspodman unshare ls -l ~/data # see files as the container user sees them
More cheat sheets
Questions
How do I run a container in the background with Podman?
Use podman run -d --name web -p 8080:8080 IMAGE. -d detaches it, --name names it and -p publishes a port.
Why do I add :Z to a Podman volume?
On SELinux systems :Z relabels the host folder so the container can use it. Use :z when several containers share the folder.
How do I run a rootless container as a systemd service?
Create a .container file in ~/.config/containers/systemd/, run systemctl --user daemon-reload, start the generated service, and run loginctl enable-linger so it survives logout.
What is the difference between a Containerfile and a Dockerfile?
They use the same syntax. Podman builds both with podman build.