Skip to content

ADR-0001: Rootless Podman is the application standard

  • Status: Accepted
  • Date: 2026-06-22

Context and decision

The restored application platform needed reproducible systemd integration and a smaller privilege boundary than the former rootful Docker host. Application containers run as podsvc in unprivileged CT 101, use Quadlets, high host ports, /opt/podman data paths, and a shared internal network.

Alternatives

Rootful Docker in CT 100, rootful Podman, or a separate LXC for every application were considered. Rootful designs increase impact; per-application LXCs add operational overhead.

Consequences

UID/GID mapping and TUN networking require care. Low ports remain with dedicated infrastructure services. Rootless volumes and user systemd must be included in backup and recovery.

Validation evidence

CT 101 was unprivileged and Podman 5.4.2 ran eight healthy/current containers as podsvc on 2026-07-17.