Podman (compose & quadlets)
The Docker & Compose guide covers the images, the volume requirement, upgrades, and most of the troubleshooting; this page is what is different under Podman.
Rootless
Section titled “Rootless”Rootless Podman is fine: the app listens on port 3000, which is above 1024, so an unprivileged user can bind it. If you remap to a port below 1024, rootless needs sysctl net.ipv4.ip_unprivileged_port_start=0 (or run privileged).
SELinux
Section titled “SELinux”On SELinux hosts (Fedora, RHEL), append :z (shared) or :Z (private) to bind mounts:
podman run -d --name galene \ -v /var/lib/galene:/app/data:Z \ -p 3000:3000 \ galene:appNamed volumes are relabeled by Podman automatically and need no suffix.
podman-compose
Section titled “podman-compose”The same docker-compose.yml works with podman-compose:
podman-compose up -dQuadlet
Section titled “Quadlet”For a systemd-managed container, a quadlet unit is the cleanest path. For a rootless user, put this in ~/.config/containers/systemd/galene.container (for a system service, /etc/containers/systemd/ instead):
[Container]Image=ghcr.io/galene-finance/galene:latestContainerName=galenePublishPort=3000:3000Volume=galene_data:/app/dataEnvironment=GALENE_COOKIE_SECURE=0
[Service]Restart=always
[Install]WantedBy=default.targetThen enable and start it:
systemctl --user daemon-reloadsystemctl --user enable --now galene.containerjournalctl --user -u galene.container -fNotes:
- The named volume
galene_datais created by Podman on first start and relabeled automatically. If you prefer a bind mount, useVolume=/path/on/host:/app/data:Z(:Zon SELinux hosts). GALENE_COOKIE_SECURE=0is for plain HTTP; set it to1behind a TLS-terminating proxy (Reverse proxy).- For a system unit, use
WantedBy=multi-user.targetandsystemctl enable --now galene.container(without--user).
Storage driver
Section titled “Storage driver”Avoid vfs — it is very slow for the SQLite WAL workload. overlay/overlay2 (the default) is what you want.
Pulling from GHCR
Section titled “Pulling from GHCR”Public images pull anonymously — no login:
podman pull ghcr.io/galene-finance/galene:latestOnly if pull fails (private package, org policy, rate limits, etc.) run podman login ghcr.io with a classic personal access token that has read:packages. Fine-grained tokens cannot authenticate to GHCR.
Troubleshooting
Section titled “Troubleshooting”| Symptom | Fix |
|---|---|
| Can’t bind a port below 1024 as a normal user | sysctl net.ipv4.ip_unprivileged_port_start=0, or use a port ≥ 1024. |
podman pull ghcr.io/… fails after a fine-grained login |
podman logout ghcr.io and pull anonymously, or use a classic PAT with read:packages. |
Everything else — the volume requirement, healthcheck, upgrades, and the cookie behavior — is the same as Docker & Compose.