• GustavoM@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      16 days ago

      As someone who has been OOTL regarding self-hosting for the last few months… what is the -real- difference between Arcane and Portainer?

      • ALERT@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        3
        ·
        16 days ago

        There are basically none. I found zero features that I was missing after the transition. More so, there are features that Arcane has, but Portainer doesn’t: notifications, container update checks, container auto-updates.

  • higgsboson@piefed.social
    link
    fedilink
    English
    arrow-up
    6
    ·
    16 days ago

    Must be a sign. Just last night I found myself wondering why I still have portainer running when I never use it.

  • pucker4676@lemmy.ml
    link
    fedilink
    arrow-up
    7
    arrow-down
    5
    ·
    16 days ago

    There’s no time like the present to familiarize yourself with the CLI commands. Docker’s pretty basic. Less is more.

    • antheraeavx@slrpnk.netOP
      link
      fedilink
      English
      arrow-up
      9
      ·
      edit-2
      16 days ago

      Saw quite a few similar comments under the original post. Enjoying user interfaces is not equivalent to being tech-illiterate. Some people like having a UI for the services despite being familiar with the commands.

      Yes, I can do docker container ls, but I like looking at a dashboard. Even better if I can apply different themes to it.

      • pucker4676@lemmy.ml
        link
        fedilink
        arrow-up
        1
        ·
        16 days ago

        You can customize the hell out of your terminal emulator. As I said in the other comment, you do you. It’s a security risk, but it’s not my box.

    • ☂️-@lemmy.ml
      link
      fedilink
      arrow-up
      5
      ·
      16 days ago

      i can manage my lab entirely by cli just fine.

      i also like having it visually on a gui

      • pucker4676@lemmy.ml
        link
        fedilink
        arrow-up
        2
        ·
        16 days ago

        I understand a GUI can be nice to look at, but it can also be a security risk. More permissions, more attack surface. It’s largely an unnecessary addition. But you do you. It’s not my box. I’m trying to migrate from docker to rootless podman. It’s been on my to-do list for quite awhile. There’s only so much segregating you can do with a rootful daemon.

        • antheraeavx@slrpnk.netOP
          link
          fedilink
          arrow-up
          2
          ·
          edit-2
          16 days ago

          You can run rootless Podman with Portainer, I do too. Or used to, before ditching Portainer.

          Can you elaborate on the ways a home lab is less secure if it runs a container management GUI? I’m open to learning more about it. What additional permissions does a GUI inherently require?

          Most companies I worked at used OpenShift in production, and I do not think it was considered an attack vector more than any other components of the ecosystem were. I would be surprised if this was a major factor when it came to security incidents.

          I don’t think that container privilege escalation vulnerabilities are correlated to the use of a GUI. To me, it is not a significant (or otherwise unique) risk. Even less so when we’re talking about a home lab that is only accessible via a VPN.

          Now, is it unnecessary? Sure, but then so is running Jellyfin or lighting a scented candle.

          • pucker4676@lemmy.ml
            link
            fedilink
            arrow-up
            2
            ·
            16 days ago

            Well, I learned something new. I didn’t know Portainer supported Podman. I guess it shouldn’t be that surprising, Cockpit does as well.

            Any time you’re giving software access to your system you’re increasing attack surface. Even with podman, if you’re running containers properly, the containers have separate users, so your management system is most likely going to need root access. Or at the very least a common group which makes the segregation a moot point.

            This topic is always going to be highly personal. Some care, some do not. If you’re only running a media server, then who cares if it’s all lost, but if you’re also hosting all your photos, sensitive documents, etc… It becomes a huge risk for everything to mingle with root access. I can’t imagine anyone would want a third party hanging out behind their firewall regardless.

  • RxBrad@infosec.pub
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    1
    ·
    15 days ago

    I opted for Dockhand instead of Arcane. It’s a whole lot less vibe coded.

    Also, switching over from Portainer was easy-peasy. Just stopped Portainer stack, paste stack & env’s into Dockhand & start it. Repeat until done. (I did have to replace any Portainer env_file: stack.envs with env_file: .env)

  • amelore@slrpnk.net
    link
    fedilink
    English
    arrow-up
    2
    ·
    15 days ago

    I also started out with Portainer and Docker, as a beginner I thought it was easy.

    I’ve not switched to a different web interface, but removed it and started using rootless podman quadlets. I do have to do some stuff myself because of this.

    • datendefekt@feddit.org
      link
      fedilink
      arrow-up
      2
      ·
      edit-2
      15 days ago

      Rootless podman is the way. Still have portainer set up because so many projects just have documentation for docker compose and just aren’t worth the pain to get them working with podman. Looking at you, immich!