Advanced
Podman
MangoDock manages Podman hosts too, with the differences named rather than discovered.
Podman management is off by default and turned on in Settings ▸ Manage. It is a server-side switch rather than a browser preference, because it decides what the whole install manages.
On, it adds a Podman entry to the sidebar listing your Podman hosts with their version, whether they run rootful or rootless, the negotiated API version, and what each one cannot do. The engine is detected from the daemon's own version response, in the same call that negotiates the API version, so knowing which engine you are talking to costs no extra round trip.
What differs
| Area | On Podman |
|---|---|
| CPU limits | Expressed in the form Podman accepts. Sending Docker's form is accepted with an empty warning and then ignored — the ceiling silently does not exist, which is why this is handled explicitly. |
| Swarm | Not available. The page says so and links here, rather than offering to initialise a cluster whose requests then fail. |
| Update checks | Not supported by the shipped daemon. MangoDock says that, rather than reporting that your registry no longer has the tag — which was a false claim about your infrastructure. Pulling still works. |
| Secrets | Work. The breakage reported elsewhere did not reproduce. |
| Compose | Verified end to end. |
Short image names depend on the host, not on MangoDock
image: alpine resolves only if docker.io is in that host's unqualified-search-registries. On a host configured without it, the same compose file fails to pull. Qualify the image name if you cannot rely on every host's configuration.
Plaintext TCP is worse here than on Docker
Podman's own service warns, unprompted, against using its API over TCP without TLS. The advice on the Adding hosts page applies with more force: use SSH, or mutual TLS.
Air-gapped
- Podman hosts are reached the same ways Docker hosts are, and the same refusal to send credentials over a plaintext connection applies.