this post was submitted on 10 Jan 2024
79 points (86.9% liked)

Selfhosted

40091 readers
893 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 1 year ago
MODERATORS
 

Hi! Question in the title.

I get that its super easy to setup. But its really worthwhile to have something that:

  • runs everything as root (not many well built images with proper useranagement it seems)
  • you cannot really know which stuff is in the images: you must trust who built it
  • lots of mess in the system (mounts, fake networks, rules...)

I always host on bare metal when I can, but sometimes (immich, I look at you!) Seems almost impossible.

I get docker in a work environment, but on self hosted? Is it really worth while? I would like to hear your opinions fellow hosters.

you are viewing a single comment's thread
view the rest of the comments
[–] Shimitar@feddit.it -5 points 10 months ago (2 children)

Need to study podman probably, stuff running as root is my main dislike.

Probably if in only used docker images created by me I would be less concerned of losing track of what I am really deploying, but this would deflect the main advantage of easy deploy?

Portability is a point I didn't considered too.. But rebuilding a bare metal server properly compatimentized took me a few hours only, so is that really so important?

[–] beta_tester@lemmy.ml 5 points 10 months ago (1 children)

You can run docker rootless https://docs.docker.com/engine/security/rootless/ but you have to switch to podman some day anyway, althiugh that might be in a far away future.

If you are concerned about root you may be concerned about the docker port dilemma as well, podman solves that as well

[–] Passerby6497@lemmy.world 2 points 10 months ago (1 children)

but you have to switch to podman some day anyway

Can you elaborate on this?

[–] beta_tester@lemmy.ml 0 points 10 months ago (1 children)

Unfortunately I do not have a source but to me it was like podman would replace docker as the container technology since red hat focuses on podman and not docker anymore and kubernetes doesn't support docker anymore. Transitioning obviously takes ages because of companies being very slow.

[–] N0x0n@lemmy.ml 1 points 10 months ago (1 children)

I hope you're wrong... With RH's recent choices in regard of FOSS... I really hope podman won't replace docker. Specially in the self-hosted/FOSS community !

[–] beta_tester@lemmy.ml 1 points 10 months ago (1 children)

What's wrong with podman?

It's still many many years away. Just think about there being still fortran or assembly code

[–] N0x0n@lemmy.ml 1 points 10 months ago (1 children)

Probably nothing, I have never tried it... but docker compose feels so comfortable right now and relearn everything... uuhhg !

[–] beta_tester@lemmy.ml 1 points 10 months ago

I had to add :Z to the paths in the docker compose files for selinux.

[–] null 4 points 10 months ago

But rebuilding a bare metal server properly compatimentized took me a few hours only, so is that really so important?

Depends on how much you value your time.

Compare a few hours on bare metal to a few minutes with containers. Then consider that you also spend extra time on bare metal cleaning up messes. Containers don't make a mess in the first place.