Podman runs containers without a central daemon: each podman invocation forks the runtime directly, and it can run fully rootless under a user's own account. That changes the attack surface from Docker's: there is no always-on root daemon, but there is an optional API service socket, a rootless model with its own escape limits, and the same OCI image and runtime primitives underneath.
Subtopics#
- API service socket: the optional Podman REST API.
- systemd socket activation: the socket exposed through systemd.
- Rootless model: the rootless user-namespace mapping and its limits.
- skopeo and buildah: the companion image tools and their credentials.