Skip to content

Podman (compose & quadlets)

The Docker & Compose guide covers the images, the volume requirement, upgrades, and most of the troubleshooting; this page is what is different under Podman.

Rootless Podman is fine: the app listens on port 3000, which is above 1024, so an unprivileged user can bind it. If you remap to a port below 1024, rootless needs sysctl net.ipv4.ip_unprivileged_port_start=0 (or run privileged).

On SELinux hosts (Fedora, RHEL), append :z (shared) or :Z (private) to bind mounts:

Terminal window
podman run -d --name galene \
-v /var/lib/galene:/app/data:Z \
-p 3000:3000 \
galene:app

Named volumes are relabeled by Podman automatically and need no suffix.

The same docker-compose.yml works with podman-compose:

Terminal window
podman-compose up -d

For a systemd-managed container, a quadlet unit is the cleanest path. For a rootless user, put this in ~/.config/containers/systemd/galene.container (for a system service, /etc/containers/systemd/ instead):

[Container]
Image=ghcr.io/galene-finance/galene:latest
ContainerName=galene
PublishPort=3000:3000
Volume=galene_data:/app/data
Environment=GALENE_COOKIE_SECURE=0
[Service]
Restart=always
[Install]
WantedBy=default.target

Then enable and start it:

Terminal window
systemctl --user daemon-reload
systemctl --user enable --now galene.container
journalctl --user -u galene.container -f

Notes:

  • The named volume galene_data is created by Podman on first start and relabeled automatically. If you prefer a bind mount, use Volume=/path/on/host:/app/data:Z (:Z on SELinux hosts).
  • GALENE_COOKIE_SECURE=0 is for plain HTTP; set it to 1 behind a TLS-terminating proxy (Reverse proxy).
  • For a system unit, use WantedBy=multi-user.target and systemctl enable --now galene.container (without --user).

Avoid vfs — it is very slow for the SQLite WAL workload. overlay/overlay2 (the default) is what you want.

Public images pull anonymously — no login:

Terminal window
podman pull ghcr.io/galene-finance/galene:latest

Only if pull fails (private package, org policy, rate limits, etc.) run podman login ghcr.io with a classic personal access token that has read:packages. Fine-grained tokens cannot authenticate to GHCR.

Symptom Fix
Can’t bind a port below 1024 as a normal user sysctl net.ipv4.ip_unprivileged_port_start=0, or use a port ≥ 1024.
podman pull ghcr.io/… fails after a fine-grained login podman logout ghcr.io and pull anonymously, or use a classic PAT with read:packages.

Everything else — the volume requirement, healthcheck, upgrades, and the cookie behavior — is the same as Docker & Compose.