Podman Desktop
by Red Hat, Inc.
Manage Podman and other container engines from a single UI
About
Podman Desktop is an open source graphical tool enabling you to seamlessly work with containers and Kubernetes from your local environment.
Build, run and manage containers:
- Build images from Containerfile or Dockerfile.
- Pull images from remote registries.
- Start, Stop, Restart containers and pods.
- Easily get a terminal in your container.
- Inspect container logs.
- Push images to OCI registries.
- Deploy and test images on Kubernetes.
Multiple configuration options
- Manage OCI registries; add, edit, or delete registries.
- Configure your proxy settings (work in progress.)
- Configure CPU, memory, and disk of Podman machines (work in progress.)
- Handle multiple container engines at the same time (Podman, Docker, Lima...)
You can also bring new features with Podman Desktop plug-ins or Docker Desktop extensions.
Permissions
6 permissions weaken the sandbox. Flatsonar asks before installing.
- access to a sensitive location (/run/docker.sock): credentials or autostart
--filesystem=/run/docker.sock - sandbox escape: can run commands on the host via flatpak-spawn
--talk-name=org.freedesktop.Flatpak - X11 display: X11 lets apps read input and windows of other apps
--socket=x11 - full access to your home folder
--filesystem=home - access to operating-system files
--filesystem=host-os:ro - your keyring / saved passwords
--talk-name=org.freedesktop.secrets - inter-process communication (needed for X11)
--share=ipc - network
--share=network - GPU acceleration
--device=dri - access to xdg-run/podman
--filesystem=xdg-run/podman:create - access to xdg-run/containers
--filesystem=xdg-run/containers:create - system tray
--talk-name=org.kde.StatusNotifierWatcher - notifications
--talk-name=org.freedesktop.Notifications - talks to org.kde.kwalletd6
--talk-name=org.kde.kwalletd6
Who publishes this
Something concrete is wrong: the id claims a namespace this repository does not own, or the build does things a build should not. Flatsonar warns twice.
- decodes an embedded blob (hidden payload): sed -i -r -e "s/SEGMENT_KEY = '.*'/SEGMENT_KEY = '$(echo -n 'ODdEZUpwVFhmU05pemF5MUNxQXhsSzViYUQ4VUE1NUQ=' | base64 --de
podman-desktop:build-commands - installs a prebuilt binary instead of building from source (x6)
source:prebuilt - verified on Flathub: the developer proved they control this app id
publisher:flathub
Maintenance
Recent activity on the upstream repository, or built and reviewed by Flathub.
No staleness signals: recent activity, or built and reviewed by Flathub.