Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It differs by not being insane. Trivial functionality that actually works. It's what's good about systemd.

It doesn't require forwarding sockets or giving free access to root just for building images. It doesn't explode just because you touch your nftables rules. It doesn't suddenly expose a process to the Internet because of some undocumented option. You can use all the normal tools such as auditd and SELinux without having your configuration overwritten by a madman.



How is it different from podman then?


It's not a docker replacement. Use podman to replace docker. Use system to start stuff (in a namespace or otherwise).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: