Podman Compose and Rootless Mode, an Update
Posted on Mon 05 October 2026 in hints-and-kinks • 2 min read
I have previously discussed my approach to running OpenCode in rootless Podman containers, based on an earlier article on the general subject.
Having recently upgraded my system to Ubuntu Resolute (which ships with Podman 5.7), I came across this curveball:
- In release 5.6, Podman started disallowing the use of
--podand--usernsin the same container, which tripped up plenty of users. - At some point (I don’t know when, exactly),
podman-composeapparently started chucking all services defined in one compose file, into one Pod. - At that point, then, it became impossible to use the
userns_mode: keep-idoption in a compose definition.
What you must now do, if you want to keep passing through your user id into a rootless container, is add this snippet to your podman-compose.yaml file:
x-podman:
in_pod: false
So, far, so good, but this only saves you if you previously put userns_mode: keep-id in your compose file.
But as you’ll recall from my previous article, there used to be another way of achieving userid passthrough, which was to set the PODMAN_USERNS environment variable.
I used to do this from a systemd user service definition, like so:
[Unit]
Description=Podman via podman-compose
Wants=network-online.target
After=network-online.target
RequiresMountsFor=%t/containers
[Service]
Environment=PODMAN_SYSTEMD_UNIT=%n
Environment=PODMAN_USERNS=keep-id
# [etc...]
And it looks like podman-compose’s behaviour has changed to effectively ignore that environment variable (even though the documentation says it’s still being honoured).
So, it looks like overall I need to follow this checklist:
- In my Compose files, add
userns_mode: keep-idto services where needed. - Add the
x-podmansection within_pod: false. - Drop the
Environment=PODMAN_USERNSline from my systemd definitions, having become a no-op.