podup
docker-compose translator and runner for rootless Podman. Reads a
docker-compose file, translates it to the native libpod REST API, and manages
the container lifecycle (up/down/logs/exec/…). A single static Rust
binary, with no daemon and no Python runtime.
Package: crates.io/crates/podup · MSRV 1.85 · License: MIT
Install
Debian / Ubuntu (apt), recommended
Register the signed Glyndor repository and install. Copy-paste:
|
The installer verifies the keyring package's Ed25519 signature against its
pinned release key before anything is installed (fail-closed). The keyring
package registers https://apt.glyndor.net and ships the signing key, so podup
updates (and key renewals) arrive through apt upgrade. The apt build omits
self-update, since apt owns upgrades. Requires Podman ≥ 5.0 (rootless) with
its API socket listening — podman itself is daemonless, but podup speaks
the libpod API:
To register the repository by hand instead, fetch the keyring and check the key's fingerprint against the one published in the apt repository README:
&&
apt, one-liner (script)
Same as above via the install script (registers the repo, then installs):
|
Linux / macOS (install script)
|
Windows (PowerShell)
irm https://glyndor.net/podup/install/windows | iex
Both installers verify the Ed25519 signature over SHA256SUMS and fail closed
otherwise.
Build from source
Self-update
podup update replaces the running binary in place only after verifying the
release's Ed25519 signature and SHA-256 checksum, failing closed otherwise. See
docs/self-update.md for the trust model.
Podman version
podup tracks the latest stable Podman and supports its last two majors,
Podman 5.x and 6.x. It talks to Podman's native libpod API, requesting the
/v5.0.0/libpod path that Podman 6 still serves; the gate is the major version
the engine reports, so it needs Podman ≥ 5.0. Both supported majors
run the integration suite in CI on every engine change (Fedora 44 for the
latest 5.x, rawhide for 6.x). Many distributions still ship 4.x, so check
podman --version and upgrade if needed. Fedora, Debian trixie/sid and recent
Ubuntu releases carry 5.x; on an older release, install or upgrade Podman
following the official guide: https://podman.io/docs/installation.
Platforms
Linux, macOS and Windows (x86_64 and arm64). On macOS and Windows podup talks to
the podman machine VM through its host-side unix:// socket or npipe://
named pipe; the socket must be local (remote tcp:///ssh:// are rejected).
Quick start
Full command reference: docs/commands.md.
Design
Rootless-native libpod API, real compose-spec support (extends, profiles,
develop.watch, inline secrets), and systemd Quadlet export. The Rust library
crate is consumed by helmly-agent;
API docs at docs.rs/podup.
sequenceDiagram
autonumber
participant Y as docker-compose.yml
participant P as podup
participant L as Podman · libpod REST
Y->>P: parse · substitute · resolve depends_on
P->>L: create networks · volumes · secrets
P->>L: start containers in order
L-->>P: health / status
P-->>Y: stack up
Benchmarks
Peak memory and per-operation latency against docker-compose and podman-compose, all three driving the same rootless Podman, same digest-pinned images, median of 10 measured runs (12 iterations, 2 warm-up discarded), on podup 3.2.1. podup is fastest in every scenario here, though three teardown rows win by less than their own standard deviation and should be read as ties; the widest gaps are the ones with many services.
| podup | docker-compose | podman-compose | |
|---|---|---|---|
| memory per command | 7.6 MiB | 28.8 MiB | 51.1 MiB |
up, 42 services |
1.10 s | 1.61 s | 6.98 s |
up, 12 services |
0.39 s | 0.50 s | 2.21 s |
config (parse only) |
9.0 ms | 46.3 ms | 117.5 ms |
Full tables and methodology: docs/benchmarks.md.
Documentation
- Commands
- Migrating from Compose
- Autostart at boot
- Benchmarks
- Self-update
- Security model
- Debian packaging
License
MIT. Report vulnerabilities privately via the Security tab, never in a public issue.