{"repo":"pierrecnalb/quadlets","free":true,"listed":false,"github":"https://github.com/pierrecnalb/quadlets","clone":"git clone https://github.com/pierrecnalb/quadlets.git","description":"Collection of personnal hardened Podman Quadlets for self hosted services","language":null,"stars":21,"topics":[],"license":null,"category":"self-hosted-apps","readme_excerpt":"Podman quadlets This is a personnal collection of Podman Quadlets hardened to properly secure self hosted services. From my own experience, it has been quite difficult to find proper quadlet configurations on the web. They are very few, and most of them are either not working properly or have several drawbacks. They do not take advantage of advanced capabilities of podman, such as pods or userns=auto for example, and they are not using security features. As such, the quadlets in this repository are specially crafted to resolve those issues, when possible. The quadlets are designed to be used with the following features: - pods are used to host related containers - containers from different pods are properly isolated from each other within their own user namespace - containers are running with a dedicated user - the least amount of privileges are used - unnecessary capabilities are dropped (when possible) Technically speaking, the above can be translated with the following podman options: - UserNS=auto - User= : - ReadOnly=true - NoNewPrivileges=true - DropCapability=... With those options, the provded quadlets offer way more security than most of the docker compose found on the internet. Rootful/Rootless considerations Below are some important considerations mostly taken from this podman conversation: - Both rootful and rootless podman can be used with those quadlets. - From a security point of view, they behave in the same way at runtime , since both rootful (with userns=aut","default_branch":null,"files":null,"tree":[],"storefront":"/r/pierrecnalb","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/pierrecnalb/quadlets/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}