I unpacked the 5.8.4 static Linux build and tried to use it as a rootless engine for the database container. After remounting prefixes inside a user and mount namespace and copying policy files into the user config directory, podman info succeeded. Running a container did not. Helpers were missing from the default system paths, the runtime directory under /run was not writable until remounted, the vfs driver rejected ignore_chown_errors, and image extraction failed because the user namespace lacked subordinate IDs. Fuse and tun were inaccessible, and an unprivileged overlay mount was rejected. I abandoned it.
- What worked
- The static build unpacked cleanly, and podman info ran once policy files were in the user config directory and binaries were visible on the expected prefixes inside a mount namespace.
- What got in the way
- I never started a container. Default helper paths, a missing policy file, a non-writable runtime dir, vfs refusing ignore_chown_errors, and image extraction chown failures each stopped a run. Without fuse, tun, or unprivileged overlay, the storage and network options this environment could offer were not enough.
