Manage containers using Podman, the daemonless container engine.

MITAuto-check: notesDevOps & Cloud

Install Podman

skills CLI
$ npx skills add BagelHole/DevOps-Security-Agent-Skills --skill podman -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install BagelHole/DevOps-Security-Agent-Skills podman --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/BagelHole/DevOps-Security-Agent-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/devops/containers/podman .claude/skills/podman && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
podman
GitHub stars
1.1k
Token cost
~1.9k tokens
SKILL.md length
274 words
Files
1
Skills in repo
44
Repo updated
First seen
Licence
MIT

At a glance

Manage containers using Podman, the daemonless container engine.

  • Working with Podman
  • SKILL.md covers When to Use This Skill, Prerequisites, Key Differences from Docker and Basic Commands, plus 8 more sections
  • Calls podman, pip and docker-compose
  • Requiring rootless container operations

What it does

Podman is an agent skill from BagelHole/DevOps-Security-Agent-Skills. Manage containers using Podman, the daemonless container engine. Run rootless containers, create pods, manage images, and use Docker-compatible commands. Use when working with Podman or requiring rootless container operations.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Containers and Linux administration. It works with Docker, Linux and Kubernetes. The repository describes itself as: Agent-ready DevOps, security, infrastructure, and compliance knowledge base with 80+ skills across Kubernetes, Terraform, AWS/Azure/GCP, AI platform operations, container… The licence is MIT.

When your agent uses it

  • Working with Podman
  • Requiring rootless container operations

Example prompts

  • “/podman”

Requirements

  • Python 3
  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit 0365f57. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • podman
    • pip
    • docker-compose

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Podman loads about 1.9k tokens when it runs. Until then it costs about 58 tokens; SKILL.md has 274 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~58
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:89
    echo "user.max_user_namespaces=28633" | sudo tee /etc/sysctl.d/userns.conf
  • NoteRuns commands with sudoSKILL.md:90
    sudo sysctl -p /etc/sysctl.d/userns.conf
  • NoteRuns commands with sudoSKILL.md:93
    sudo usermod --add-subuids 100000-165535 --add-subgids 100000-165535 $USER
  • NoteRuns commands with sudoSKILL.md:120
    et.ipv4.ip_unprivileged_port_start=80" | sudo tee /etc/sysctl.d/ports.conf
  • NoteRuns commands with sudoSKILL.md:121
    sudo sysctl -p /etc/sysctl.d/ports.conf

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from BagelHole/DevOps-Security-Agent-Skills at commit 0365f57, republished under its MIT licence (© BagelHole). 274 words, ~1,948 tokens.

Download SKILL.mdSave it as .claude/skills/podman/SKILL.md (or your agent's skills folder).
name
podman
description
Manage containers using Podman, the daemonless container engine. Run rootless containers, create pods, manage images, and use Docker-compatible commands. Use when working with Podman or requiring rootless container operations.
license
MIT
metadata.author
devops-skills
metadata.version
1.0

Podman

Run and manage containers without a daemon using Podman's rootless container engine.

When to Use This Skill

Use this skill when:

  • Running containers without root privileges
  • Managing containers on systems without Docker
  • Creating pod-based container groups
  • Using systemd for container management
  • Working in security-conscious environments

Prerequisites

  • Podman installed (4.x+)
  • For rootless: user namespaces enabled
  • Basic container concepts understanding

Key Differences from Docker

FeatureDockerPodman
ArchitectureClient-daemonDaemonless
Root requiredDefaultOptional (rootless)
Pod supportNoYes (Kubernetes-style)
Systemd integrationLimitedNative
Socketdocker.sockpodman.sock (optional)

Basic Commands

Container Operations
bash
# Run container (identical to Docker)
podman run -d --name webserver -p 8080:80 nginx

# List containers
podman ps -a

# Stop and remove
podman stop webserver
podman rm webserver

# Execute command
podman exec -it webserver /bin/sh

# View logs
podman logs -f webserver
Image Management
bash
# Pull image
podman pull docker.io/library/nginx:latest

# List images
podman images

# Build image
podman build -t myapp:latest .

# Push to registry
podman push myapp:latest registry.example.com/myapp:latest

# Remove image
podman rmi nginx:latest

Rootless Containers

Setup
bash
# Check user namespace support
cat /proc/sys/user/max_user_namespaces

# Enable if needed (as root)
echo "user.max_user_namespaces=28633" | sudo tee /etc/sysctl.d/userns.conf
sudo sysctl -p /etc/sysctl.d/userns.conf

# Configure subuid/subgid for user
sudo usermod --add-subuids 100000-165535 --add-subgids 100000-165535 $USER

# Verify
podman unshare cat /proc/self/uid_map
Running Rootless
bash
# Run as regular user (no sudo)
podman run -d --name myapp -p 8080:80 nginx

# Check user namespace mapping
podman unshare id

# Verify non-root
podman top myapp user
Port Considerations
bash
# Rootless cannot bind to ports < 1024 by default
# Use ports >= 1024
podman run -d -p 8080:80 nginx

# Or enable unprivileged ports (as root)
echo "net.ipv4.ip_unprivileged_port_start=80" | sudo tee /etc/sysctl.d/ports.conf
sudo sysctl -p /etc/sysctl.d/ports.conf

Pods

Creating Pods
bash
# Create pod
podman pod create --name mypod -p 8080:80 -p 5432:5432

# Add containers to pod
podman run -d --pod mypod --name web nginx
podman run -d --pod mypod --name db postgres:15

# List pods
podman pod ps

# Containers share network namespace
podman exec web curl localhost:5432
Pod Management
bash
# Start/stop pod (affects all containers)
podman pod start mypod
podman pod stop mypod

# Remove pod and containers
podman pod rm -f mypod

# View pod details
podman pod inspect mypod

# Generate Kubernetes YAML from pod
podman generate kube mypod > mypod.yaml

Systemd Integration

Generate Systemd Unit
bash
# Generate unit file for container
podman generate systemd --new --name myapp > ~/.config/systemd/user/container-myapp.service

# For pod
podman generate systemd --new --name mypod --files

# Reload systemd
systemctl --user daemon-reload

# Enable and start
systemctl --user enable --now container-myapp.service
Quadlet (Podman 4.4+)
ini
# ~/.config/containers/systemd/webapp.container
[Container]
Image=docker.io/library/nginx:latest
PublishPort=8080:80
Volume=webapp-data:/usr/share/nginx/html

[Service]
Restart=always

[Install]
WantedBy=default.target
bash
# Reload to generate service
systemctl --user daemon-reload

# Start the service
systemctl --user start webapp

Compose Compatibility

Using Podman Compose
bash
# Install podman-compose
pip install podman-compose

# Run compose file
podman-compose up -d

# Or use Docker Compose with Podman socket
systemctl --user enable --now podman.socket
export DOCKER_HOST=unix:///run/user/$UID/podman/podman.sock
docker-compose up -d
Native Podman Kube
bash
# Play Kubernetes YAML
podman kube play deployment.yaml

# Stop and remove
podman kube down deployment.yaml

Networking

Network Management
bash
# Create network
podman network create mynetwork

# Run on network
podman run -d --network mynetwork --name app myapp

# Connect container to network
podman network connect mynetwork existing-container

# List networks
podman network ls

# Inspect network
podman network inspect mynetwork
DNS Resolution
bash
# Containers on same network can resolve by name
podman run -d --network mynetwork --name db postgres:15
podman run -d --network mynetwork --name app \
  -e DATABASE_HOST=db myapp

Storage

Volume Management
bash
# Create volume
podman volume create mydata

# Use volume
podman run -d -v mydata:/data myapp

# List volumes
podman volume ls

# Inspect volume
podman volume inspect mydata

# Rootless volumes location
ls ~/.local/share/containers/storage/volumes/
Bind Mounts
bash
# Bind mount with SELinux label
podman run -v ./data:/app/data:Z myapp

# Z = private label (single container)
# z = shared label (multiple containers)

Registry Configuration

Configure Registries
bash
# Edit registries.conf
# ~/.config/containers/registries.conf
toml
unqualified-search-registries = ["docker.io", "quay.io"]

[[registry]]
prefix = "docker.io"
location = "docker.io"

[[registry.mirror]]
location = "mirror.gcr.io"
Authentication
bash
# Login to registry
podman login docker.io

# Login to private registry
podman login registry.example.com

# Credentials stored in
# ~/.config/containers/auth.json

Building Images

Buildah Integration
bash
# Podman uses Buildah for builds
podman build -t myapp:latest .

# Build with specific format
podman build --format docker -t myapp .

# Multi-stage build
podman build --target production -t myapp:prod .
Buildah Commands
bash
# Create container from scratch
buildah from scratch
buildah copy working-container ./app /app
buildah config --entrypoint '["/app/main"]' working-container
buildah commit working-container myapp:minimal

Common Issues

Issue: Permission Denied

Problem: Cannot access files in mounted volumes Solution: Use :Z or :z suffix for SELinux, or check ownership

Issue: Cannot Connect to Container

Problem: Port not accessible in rootless mode Solution: Use ports >= 1024 or configure unprivileged port start

Issue: Slow Image Pulls

Problem: Images download slowly Solution: Configure registry mirrors in registries.conf

Issue: Systemd Service Fails

Problem: Container doesn't start via systemd Solution: Enable lingering: loginctl enable-linger $USER

Best Practices

  • Use rootless mode for enhanced security
  • Leverage pods for related containers
  • Generate systemd units for production
  • Use Quadlet for declarative container services
  • Configure SELinux labels for bind mounts
  • Enable user lingering for persistent services
  • Use podman auto-update for automatic updates
  • Alias docker to podman for compatibility

© BagelHole, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in devops/containers/podman of BagelHole/DevOps-Security-Agent-Skills.

Open the folder on GitHubat commit 0365f57

Compare with similar skills

Podman next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Podman compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Podman this skillBagelHole/DevOps-Security-Agent-Skills1.1k—~1.9kAutomated safety check: NotesMIT
Podmansickn33/agentic-awesome-skills47k1 repos~2.2kAutomated safety check: NotesMIT
GitHub Runnermagnus919/agent-skills116—~1.7kAutomated safety check: PassMIT
.NET Crash Dump Collectiondotnet/skills5.6k2 repos~1.1kAutomated safety check: PassMIT
Minimegasandia-minimega/minimega160—~3.2kAutomated safety check: PassGPL-3.0-only
Devsydevsy-org/devsy111—~1.7kAutomated safety check: PassMPL-2.0

Similar skills

  • Podman

    sickn33/agentic-awesome-skills

    Manage containers using Podman, the daemonless container engine.

    47k GitHub starsUsed in 1 repo~2.2k tokens
    DevOps & CloudAuto-check: notes
  • GitHub Runner

    magnus919/agent-skills

    Deploy, manage, and troubleshoot self-hosted GitHub Actions runners.

    116 GitHub stars~1.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Official

    Configures automatic crash dumps or captures dumps from running processes for modern .NET apps on Linux, macOS and Windows, including Docker and Kubernetes.

    5.6k GitHub starsUsed in 2 repos~1.1k tokens
    DevOps & CloudAuto-check passed
  • Minimega

    sandia-minimega/minimega

    This skill should be used when the user asks how to configure, run, automate, integrate, or troubleshoot minimega (VMs, namespaces, VLANs, clusters, miniccc, miniweb, command socket or Python API…

    160 GitHub stars~3.2k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Devsy

    devsy-org/devsy

    Operate Devsy workspaces and providers for end users. An agent skill from devsy-org/devsy.

    111 GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Setup Cpu Proxy Server

    drawthingsai/draw-things-community

    Set up and verify a new Draw Things CPU proxy and Envoy server using the scripts in Scripts/ServerManagement/CPUScript.

    582 GitHub stars~3.8k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from BagelHole/DevOps-Security-Agent-Skills

All 44 skills in this repo
  • Hashicorp Vault

    BagelHole/DevOps-Security-Agent-Skills

    Manage secrets and PKI with HashiCorp Vault. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.1k GitHub stars~2k tokensUpdated 4 mo ago
    Auto-check passed
  • Incident Response

    BagelHole/DevOps-Security-Agent-Skills

    Handle security incidents with IR playbooks and procedures. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.1k GitHub stars~4.5k tokensUpdated 4 mo ago
    Auto-check passed
  • Kubernetes Ops

    BagelHole/DevOps-Security-Agent-Skills

    Deploy, scale, and manage Kubernetes workloads. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.1k GitHub stars~2.3k tokensUpdated 4 mo ago
    Auto-check passed
  • Linux Hardening

    BagelHole/DevOps-Security-Agent-Skills

    Apply CIS benchmarks and secure Linux servers. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.1k GitHub stars~662 tokensUpdated 4 mo ago
    Auto-check: notes
  • Prometheus Grafana

    BagelHole/DevOps-Security-Agent-Skills

    Set up metrics collection and visualization with Prometheus and Grafana.

    1.1k GitHub stars~2.5k tokensUpdated 4 mo ago
    Auto-check passed
  • Vulnerability Scanning

    BagelHole/DevOps-Security-Agent-Skills

    Scan systems and dependencies for CVEs and security vulnerabilities.

    1.1k GitHub stars~2.4k tokensUpdated 4 mo ago
    Auto-check passed

Categories

Questions about Podman

What does Podman do?

Manage containers using Podman, the daemonless container engine. Podman is an agent skill from BagelHole/DevOps-Security-Agent-Skills. Manage containers using Podman, the daemonless container engine.

When should I use Podman?

Podman fits situations like: working with Podman; requiring rootless container operations.

How do I install Podman in Claude Code?

Run `npx skills add BagelHole/DevOps-Security-Agent-Skills --skill podman -a claude-code`. Or copy the skill folder (devops/containers/podman in BagelHole/DevOps-Security-Agent-Skills) into .claude/skills/podman in your project. Claude Code loads it when a task matches its description.

How do I install Podman in Codex?

Run `npx skills add BagelHole/DevOps-Security-Agent-Skills --skill podman -a codex`. Or copy the skill folder (devops/containers/podman in BagelHole/DevOps-Security-Agent-Skills) into .agents/skills/podman in your project. Codex loads it when a task matches its description.

Can I use Podman in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BagelHole/DevOps-Security-Agent-Skills --skill podman -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/podman, .gemini/skills/podman, .github/skills/podman and .opencode/skills/podman in your project.

What does Podman need to run?

Going by SKILL.md and its folder, Podman needs the command-line tools its instructions call (podman, pip and docker-compose). Our summary lists: Python 3; Docker.

Does Podman access the network?

SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Podman safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Podman use?

Podman is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Podman use?

About 1.9k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Podman?

Skills that share tags, products or a category with Podman: Podman (sickn33/agentic-awesome-skills, 47k stars), GitHub Runner (magnus919/agent-skills, 116 stars), .NET Crash Dump Collection (dotnet/skills, 5.6k stars) and Minimega (sandia-minimega/minimega, 160 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Podman?

BagelHole (a GitHub user) maintains it in BagelHole/DevOps-Security-Agent-Skills, which has 1,148 GitHub stars. The repository holds 44 skills in this directory. The repository was last updated on May 22, 2026.

Source: BagelHole/DevOps-Security-Agent-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.