Skip to content

Setup

Setup

As stated already, this resource focuses primarily on Podman and rpm based operating systems.

  • RPM-based distributions are Linux distributions that use the RPM Package Manager (originally Red Hat Package Manager, now a recursive acronym) as their core system for installing, updating, managing, and removing software.

  • The RPM ecosystem forms the backbone of the enterprise Linux world, heavily favored in corporate data centers, cloud infrastructure, and commercial servers.

  • It has the first class support for Podman, systemd1, and SELinux2.

Since SELinux, systemd, and Podman co-engineered, it has the tightest integration a system can ever have.

When choosing a distribution it is recommended to choose from

  • Alma Linux
  • CentOS Stream
  • Fedora
  • Rock Linux
  • RHEL
  • SUSE / openSUSE (Tumbleweed / Leap) : SUSE historically chose apparmor instead of SELinux and it is getting shifted to SELinux therefor, choose a version that has SELinux by defauly

Prepare the system

After installing the operating system, the packages and system updates are often older. It is recommended to update it before proceeding.

Unlike Debian based operating systems, rpm distros are updated in a single command rather than upgrade && update.

  • Common: Almalinux / CentOS / Fedora / Rockylinux / RHEL
  • Atomic: Almalinux Bootc / Fedora Atomic / RHEL For Edge
  • Suse: SLE and others
sudo dnf -y update && \
podman -v  || sudo dnf install -y podman && \
skopeo -v  || sudo dnf install -y skopeo && \
buildah -v || sudo dnf install -y buildah && \
udica -v   || sudo dnf install -y udica \
rpm-ostree update && \
podman -v  || rpm-ostree install -y podman && \
skopeo -v  || rpm-ostree install -y skopeo && \
buildah -v || rpm-ostree install -y buildah && \
udica -v   || rpm-ostree install -y udica \
sudo zypper -y update && \
podman -v  || sudo zypper install -y podman && \
skopeo -v  || sudo zypper install -y skopeo && \
buildah -v || sudo zypper install -y buildah && \
udica -v   || sudo zypper install -y udica \

Footnotes

  1. systemd is a system and service manager for Linux operating systems that starts and controls user-space processes after the kernel boots. systemd is a modern replacement for the traditional sysvinit (SysV init) process. While it replaces the old sysvinit system, it retains compatibility with legacy SysV init scripts in most configurations, allowing older software to boot seamlessly alongside modern systemd services. ↩

  2. SELinux (Security-Enhanced Linux) is a Linux kernel security module that provides a mechanism for supporting access control security policies. Traditional Linux uses Discretionary Access Control (DAC), which relies on file ownership and permissions (rwx-rwx-rwx). If a process runs as the root user, it has access to almost everything. SELinux adds a security layer on top of it as ,

    • Least privilege by default: Even if a process runs as root, SELinux blocks it unless a specific policy explicitly permits the action.
    • Security Contexts (Labels): Every file, process, user, and network port is assigned an SELinux label therefor, it is easy and possible restrict nearly anything.
    • Type Enforcement: SELinux primarily looks at the type label. If a label does not match what the program trying to do, SELinux will forbid it.
    ↩
Navigation

Type to search…

↑↓ navigate↵ selectEsc close