@ikkeT Migrated one machine, running this gotosocial instane among others, back from k3s to Podman. Looks like during the k3s exodus Podman vas updated to v5 with Pasta rootless networking on EL9.

Decided to try NGINX in a rootless pod instead of on the host like before. That was a difficult ride... The only way I could figure out how to have IPv6 and have real src IPs (in the NGINX pod):

- NGINX in the host network ns
- A separate IPv6-enabled container network for app pods
- All app pods still expose ports on the host
- NGINX proxy_pass to "localhost:port"

Any idea if the host ports for app pods could be avoided? It was late, so I may have missed something obvious.

#podman #pods #passt #rootlesscontainers #rootless
Building a Segmented, Secure Multi-Container Application with Podman

By DeadSwitch | The Cyber Ghost”In silence, we rise. In the switch, we fade.” Modern web applications are never just one service.They’re a fortress of moving parts – and every con…

Tom's IT Cafe
Use Podman. Model your application. Segment. Contain. Secure.

By DeadSwitch | The Cyber Ghost”In silence, we rise. In the switch, we fade.” Too many teams still treat containers like virtual machines.Worse – like junk drawers.Everything in o…

Tom's IT Cafe