← All TILs · podman

Root vs rootless Podman on RHEL 10 and Ubuntu 26.04

podman - 2026-09-13

Podman has no daemon either way — root and rootless are two different ways of running the same podman binary, distinguished by whether the containers it starts get a real root-owned process on the host or one mapped into a Linux user namespace. Same commands, same image format; different storage path, different capabilities, different default posture per distro.

The core mechanism (same on every distro)

RHEL 10

Podman ships as a first-class package in the base repos, not an add-on, and RHEL's own docs treat rootless as the expected way to run containers — there's a dedicated "Special considerations for rootless containers" section in the official guide, not just a footnote. SELinux is enforcing by default, so bind-mounted host paths generally need an :z/:Z relabel suffix to be readable inside the container, rootless or not.

Ubuntu 26.04 LTS ("Resolute")

Podman is packaged in universe, Ubuntu's community-maintained tier — not main, and not Canonical's own default container tooling the way it is Red Hat's. It's a real, current package (5.7.0 in 26.04 at release), but you're relying on Debian/Ubuntu's packaging team rather than upstream Red Hat integration for how quickly it tracks new Podman releases. The user-namespace/subuid mechanics are identical (it's a kernel feature, not a distro one); the confinement layer is AppArmor instead of SELinux, so there's no :z/:Z relabeling step, but any custom AppArmor profile on the host still applies to what a container can do.

The practical takeaway

The rootless mechanism is the same everywhere Podman runs — it's Linux user namespaces plus /etc/subuid//etc/subgid, full stop. What actually differs between these two is packaging posture: RHEL treats Podman and rootless-by-default as the supported, documented path; Ubuntu treats it as a community package you opted into, so double-check its universe version against upstream before assuming a fix or feature described in Podman's own docs has landed yet.

Reference reading

Created 2026-09-13T19:55:31+02:00 · Edit