Skip to content
abdallahmekky

CHEAT SHEET

Podman cheat sheet

Run, inspect and build containers with Podman, then turn them into systemd services with Quadlet.

All cheat sheets

Images

podman pull registry.access.redhat.com/ubi9/ubi      # download an imagepodman images                                        # list local imagespodman rmi IMAGE                                     # remove an imagepodman login registry.redhat.io                      # sign in to a registryskopeo inspect docker://registry.access.redhat.com/ubi9/ubi    # look without pulling

Running containers

podman run -it --rm registry.access.redhat.com/ubi9/ubi bash     # throwaway shellpodman run -d --name web -p 8080:8080 registry.access.redhat.com/ubi9/httpd-24podman run -e KEY=value IMAGE                                    # an environment variablepodman run -v /data:/data:Z IMAGE                                # a volume (:Z fixes the SELinux label)podman ps                                                        # running containerspodman ps -a                                                     # including stopped ones

Managing containers

podman logs -f web              # follow the logspodman exec -it web bash        # a shell inside a running containerpodman stop web                 # stop itpodman start web                # start it againpodman restart web              # restart itpodman rm web                   # remove itpodman inspect web              # full details as JSONpodman port web                 # published portspodman system prune             # remove unused data

Building images

FROM registry.access.redhat.com/ubi9/ubiRUN dnf -y install httpd && dnf clean allCOPY index.html /var/www/html/EXPOSE 80CMD ["httpd", "-DFOREGROUND"]
podman build -t web:1.0 .           # build from the Containerfile in this folderpodman tag web:1.0 registry.example.com/web:1.0podman push registry.example.com/web:1.0

Quadlet: containers as systemd services

# ~/.config/containers/systemd/web.container   (rootful: /etc/containers/systemd/)[Unit]Description=Web container[Container]Image=registry.access.redhat.com/ubi9/httpd-24PublishPort=8080:8080[Install]WantedBy=default.target
systemctl --user daemon-reload       # generate web.service from web.containersystemctl --user start web.service   # start itsystemctl --user status web.service  # check itloginctl enable-linger alice         # keep user services running after logout

Volumes and networks

podman volume create data            # a named volumepodman volume ls                     # list volumespodman network ls                    # list networkspodman unshare ls -l ~/data          # see files as the container user sees them

More cheat sheets

Questions

How do I run a container in the background with Podman?

Use podman run -d --name web -p 8080:8080 IMAGE. -d detaches it, --name names it and -p publishes a port.

Why do I add :Z to a Podman volume?

On SELinux systems :Z relabels the host folder so the container can use it. Use :z when several containers share the folder.

How do I run a rootless container as a systemd service?

Create a .container file in ~/.config/containers/systemd/, run systemctl --user daemon-reload, start the generated service, and run loginctl enable-linger so it survives logout.

What is the difference between a Containerfile and a Dockerfile?

They use the same syntax. Podman builds both with podman build.