• moonpiedumplings
    link
    fedilink
    arrow-up
    2
    ·
    edit-2
    1 year ago

    Yeah that’s a gripe of mine. Thankfully podman doesn’t do that.

    Docker also sometimes breaks lxd and libvirt networking by changing the default forward policy from accept to drop.

    • saiarcot895
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 year ago

      I think podman by default does do that, but it’s easy to disable almost all of it, at least.

      • moonpiedumplings
        link
        fedilink
        arrow-up
        1
        ·
        1 year ago

        Nope, I just tested and the rootful podman service doesn’t touch any iptables/firewall rules.

        It uses what is called a “CNI”, container network interface, to manage container networking rather than just overwriting all the iptables rules like docker does.