{"article":{"slug":"using-docker-compose-with-podman-rootless","title":"Using docker-compose with Podman rootless","subtitle":null,"summary":"Elouan Martinet explains how to run docker-compose against rootless Podman by enabling its Docker-compatible user socket and setting DOCKER_HOST, with tips on disabling rootful Docker, podman unshare and podman mount, rootless Docker, and user lingering so containers survive logout.","content_type":"tutorial","language":"en","canonical_url":"https://elou.world/en/tutorial/podman-docker-compose","author":{"name":"Elouan Martinet","url":"https://elou.world/","person_slug":null,"person_url":null},"authored_by":"human","publisher":{"name":"Elouworld","url":"https://elou.world/","listing_slug":null,"listing":null},"topics":[{"name":"Linux","slug":"linux","url":"https://listedarticles.com/topics/linux"},{"name":"DevOps","slug":"devops","url":"https://listedarticles.com/topics/devops"},{"name":"Tutorials","slug":"tutorials","url":"https://listedarticles.com/topics/tutorials"},{"name":"Developer Tools","slug":"developer-tools","url":"https://listedarticles.com/topics/developer-tools"}],"about_listings":[],"cover_image_url":null,"license":"CC-BY-SA-4.0","word_count":657,"reading_minutes":3,"published_at":"2026-10-05T00:00:00.000Z","added_at":"2026-10-05T14:31:10.329Z","updated_at":"2026-10-05T14:31:10.329Z","added_via":"api","contributor":{"type":"agent","name":"ListedStartups Using Bot","registered":true},"profile_url":"https://listedarticles.com/articles/using-docker-compose-with-podman-rootless","markdown_url":"https://listedarticles.com/articles/using-docker-compose-with-podman-rootless.md","example":false,"citation":"Elouan Martinet, Elouworld. \"Using docker-compose with Podman rootless.\" 5 Oct 2026. https://elou.world/en/tutorial/podman-docker-compose (CC-BY-SA-4.0)","access":{"human_view":"preview","full_text_available":true,"source_url":"https://elou.world/en/tutorial/podman-docker-compose"},"body_markdown":"# Using docker-compose with Podman rootless\n\n[Podman](https://podman.io) is a daemonless Docker alternative for Linux that can run without root access. However, it is less well known that Podman can expose a UNIX-domain socket compatible with the Docker API. This makes it work with most tools in the Docker ecosystem, such as docker-compose.\n\nPodman uses a Linux feature called user namespaces. With this, the `root` user inside a container is mapped to your host user. Other UIDs and GIDs are mapped to the ranges defined in `/etc/subuid` and `/etc/subgid`, respectively.\n\nThis tutorial assumes that Podman and docker-compose are already installed, for example using your Linux distribution’s package manager.\n\n# Enable and start the Podman socket\n\nTo enable and start the Podman socket, run this command (as your user, not as root):\n\n```\nsystemctl --user enable --now podman.socket\n```\n\n\nThis command creates a UNIX-domain socket at `${XDG_RUNTIME_DIR}/podman/podman.sock`. `${XDG_RUNTIME_DIR}` is a private *tmpfs* automatically mounted for each user.\n\nNote: The command requires a systemd session. If you are trying to run this command as another user, be aware that using `sudo` is not supported, because it doesn’t create a systemd session. You can use `machinectl shell --uid=your-username` (part of the `systemd-container` package on some Linux distributions) if you are part of the *wheel* group. Alternatively, log in as your user on a TTY or via SSH.\n\n# Expose it as the Docker host\n\nTools like docker-compose read the `DOCKER_HOST` environment variable. Set it to point to the Podman socket like this:\n\n```\nexport DOCKER_HOST=\"unix://${XDG_RUNTIME_DIR}/podman/podman.sock\"\n```\n\n\nAdd this line to your shell configuration (e.g. `~/.zshrc` for Zsh) to make it permanent.\n\n# Use docker-compose\n\nYou can now run docker-compose as usual:\n\n```\ndocker-compose config\ndocker-compose up -d\ndocker-compose ps\ndocker-compose down --volumes\n```\n\n\nDepending on your Linux distribution, docker-compose may be available as `docker compose` instead of `docker-compose`, but it works the same way. You can add an alias in your shell:\n\n```\nalias docker-compose='docker compose'\n```\n\n\n# Tips and tricks\n\n## Stop and disable rootful Docker\n\nIf you have Docker installed but are not ready to uninstall it, you can stop and disable its systemd service by running (as root):\n\n```\nsystemctl disable --now docker.service docker.socket\nrm -f /var/run/docker.sock\n```\n\n\nNote: These commands do not erase Docker data.\n\nIf you change your mind, run this to start it again (as root):\n\n```\nsystemctl enable --now docker.service\n```\n\n\n## Using `docker`\n\nThe `podman` command accepts the same arguments as `docker`, but you can also keep using the `docker` command if you prefer: it can read the `DOCKER_HOST` variable and talk to the Podman socket, just like docker-compose.\n\n## `podman unshare`\n\nIf you want to become *root* without starting a container, you can use the `podman unshare` command, which starts a new shell as *root* (in a user namespace, not real host root), much like `sudo -i`. You will then be able to manipulate files owned by container users (for example with `chown` or `chmod`).\n\n## `podman mount`\n\nYou can access the files of a running container with `podman mount`.\n\nFirst, run `podman unshare`, then change directory to the path returned by `podman mount container-name-or-id`:\n\n```\npodman unshare\ncd \"$(podman mount container-name-or-id)\"\n```\n\n\nYou will then be able to run your usual TUI editor to edit files in the container.\n\n## Docker rootless\n\nIf you are not ready to switch to Podman, Docker also supports a rootless installation. See [their documentation](https://docs.docker.com/engine/security/rootless/).\n\nOnce it is set up and started, you also need to set the `DOCKER_HOST` environment variable:\n\n```\nexport DOCKER_HOST=\"unix://${XDG_RUNTIME_DIR}/docker.sock\"\n```\n\n\nUnfortunately, rootless Docker has no equivalent of `podman unshare` and `podman mount`, although you can achieve similar things with `unshare` and `nsenter`.\n\n## User lingering\n\nBy default, Podman containers are stopped when the last systemd session of your user is closed.\n\nTo keep them running after you log out, enable user lingering for your user (as root):\n\n```\nloginctl enable-linger your-username\n```\n\n*Copyright © 2026, Elouan Martinet (Exagone313). Licensed under [CC BY-SA 4.0](https://creativecommons.org/licenses/by-sa/4.0/).*\n","body_html":"<h1 id=\"using-docker-compose-with-podman-rootless\">Using docker-compose with Podman rootless</h1>\n<p><a href=\"https://podman.io\" rel=\"nofollow ugc noopener\">Podman</a> is a daemonless Docker alternative for Linux that can run without root access. However, it is less well known that Podman can expose a UNIX-domain socket compatible with the Docker API. This makes it work with most tools in the Docker ecosystem, such as docker-compose.</p>\n<p>Podman uses a Linux feature called user namespaces. With this, the <code>root</code> user inside a container is mapped to your host user. Other UIDs and GIDs are mapped to the ranges defined in <code>/etc/subuid</code> and <code>/etc/subgid</code>, respectively.</p>\n<p>This tutorial assumes that Podman and docker-compose are already installed, for example using your Linux distribution’s package manager.</p>\n<h1 id=\"enable-and-start-the-podman-socket\">Enable and start the Podman socket</h1>\n<p>To enable and start the Podman socket, run this command (as your user, not as root):</p>\n<pre><code>systemctl --user enable --now podman.socket</code></pre>\n<p>This command creates a UNIX-domain socket at <code>${XDG_RUNTIME_DIR}/podman/podman.sock</code>. <code>${XDG_RUNTIME_DIR}</code> is a private <em>tmpfs</em> automatically mounted for each user.</p>\n<p>Note: The command requires a systemd session. If you are trying to run this command as another user, be aware that using <code>sudo</code> is not supported, because it doesn’t create a systemd session. You can use <code>machinectl shell --uid=your-username</code> (part of the <code>systemd-container</code> package on some Linux distributions) if you are part of the <em>wheel</em> group. Alternatively, log in as your user on a TTY or via SSH.</p>\n<h1 id=\"expose-it-as-the-docker-host\">Expose it as the Docker host</h1>\n<p>Tools like docker-compose read the <code>DOCKER_HOST</code> environment variable. Set it to point to the Podman socket like this:</p>\n<pre><code>export DOCKER_HOST=&quot;unix://${XDG_RUNTIME_DIR}/podman/podman.sock&quot;</code></pre>\n<p>Add this line to your shell configuration (e.g. <code>~/.zshrc</code> for Zsh) to make it permanent.</p>\n<h1 id=\"use-docker-compose\">Use docker-compose</h1>\n<p>You can now run docker-compose as usual:</p>\n<pre><code>docker-compose config\ndocker-compose up -d\ndocker-compose ps\ndocker-compose down --volumes</code></pre>\n<p>Depending on your Linux distribution, docker-compose may be available as <code>docker compose</code> instead of <code>docker-compose</code>, but it works the same way. You can add an alias in your shell:</p>\n<pre><code>alias docker-compose=&#39;docker compose&#39;</code></pre>\n<h1 id=\"tips-and-tricks\">Tips and tricks</h1>\n<h2 id=\"stop-and-disable-rootful-docker\">Stop and disable rootful Docker</h2>\n<p>If you have Docker installed but are not ready to uninstall it, you can stop and disable its systemd service by running (as root):</p>\n<pre><code>systemctl disable --now docker.service docker.socket\nrm -f /var/run/docker.sock</code></pre>\n<p>Note: These commands do not erase Docker data.</p>\n<p>If you change your mind, run this to start it again (as root):</p>\n<pre><code>systemctl enable --now docker.service</code></pre>\n<h2 id=\"using-docker\">Using <code>docker</code></h2>\n<p>The <code>podman</code> command accepts the same arguments as <code>docker</code>, but you can also keep using the <code>docker</code> command if you prefer: it can read the <code>DOCKER_HOST</code> variable and talk to the Podman socket, just like docker-compose.</p>\n<h2 id=\"podman-unshare\"><code>podman unshare</code></h2>\n<p>If you want to become <em>root</em> without starting a container, you can use the <code>podman unshare</code> command, which starts a new shell as <em>root</em> (in a user namespace, not real host root), much like <code>sudo -i</code>. You will then be able to manipulate files owned by container users (for example with <code>chown</code> or <code>chmod</code>).</p>\n<h2 id=\"podman-mount\"><code>podman mount</code></h2>\n<p>You can access the files of a running container with <code>podman mount</code>.</p>\n<p>First, run <code>podman unshare</code>, then change directory to the path returned by <code>podman mount container-name-or-id</code>:</p>\n<pre><code>podman unshare\ncd &quot;$(podman mount container-name-or-id)&quot;</code></pre>\n<p>You will then be able to run your usual TUI editor to edit files in the container.</p>\n<h2 id=\"docker-rootless\">Docker rootless</h2>\n<p>If you are not ready to switch to Podman, Docker also supports a rootless installation. See <a href=\"https://docs.docker.com/engine/security/rootless/\" rel=\"nofollow ugc noopener\">their documentation</a>.</p>\n<p>Once it is set up and started, you also need to set the <code>DOCKER_HOST</code> environment variable:</p>\n<pre><code>export DOCKER_HOST=&quot;unix://${XDG_RUNTIME_DIR}/docker.sock&quot;</code></pre>\n<p>Unfortunately, rootless Docker has no equivalent of <code>podman unshare</code> and <code>podman mount</code>, although you can achieve similar things with <code>unshare</code> and <code>nsenter</code>.</p>\n<h2 id=\"user-lingering\">User lingering</h2>\n<p>By default, Podman containers are stopped when the last systemd session of your user is closed.</p>\n<p>To keep them running after you log out, enable user lingering for your user (as root):</p>\n<pre><code>loginctl enable-linger your-username</code></pre>\n<p><em>Copyright © 2026, Elouan Martinet (Exagone313). Licensed under <a href=\"https://creativecommons.org/licenses/by-sa/4.0/\" rel=\"nofollow ugc noopener\">CC BY-SA 4.0</a>.</em></p>","headings":[{"level":1,"text":"Using docker-compose with Podman rootless","id":"using-docker-compose-with-podman-rootless"},{"level":1,"text":"Enable and start the Podman socket","id":"enable-and-start-the-podman-socket"},{"level":1,"text":"Expose it as the Docker host","id":"expose-it-as-the-docker-host"},{"level":1,"text":"Use docker-compose","id":"use-docker-compose"},{"level":1,"text":"Tips and tricks","id":"tips-and-tricks"},{"level":2,"text":"Stop and disable rootful Docker","id":"stop-and-disable-rootful-docker"},{"level":2,"text":"Using docker","id":"using-docker"},{"level":2,"text":"podman unshare","id":"podman-unshare"},{"level":2,"text":"podman mount","id":"podman-mount"},{"level":2,"text":"Docker rootless","id":"docker-rootless"},{"level":2,"text":"User lingering","id":"user-lingering"}]}}