I Tried This Home Lab App Store and It Made Podman Much Easier

App store for podman 2

I have been flirting around with Podman in my home lab and have been testing it more than in the past as of recently. You may have seen my recent post on Podman Quadlets which I think have started to make Podman make more sense for me: Why Quadlets Finally Made Podman Click for Me in the Home Lab. However, it is really all about the applications in a home lab. Most of us don’t play around with Docker Compose or Quadlets just for the sake of playing around with them. Our aim is to get apps up and running. Recently, I tried out an app called Yantr in the home lab. Its sole purpose is spinning up home lab apps on rootless Podman environments. Let’s check out what it is and how you get it going.

What is Yantr?

Yantr is a self-hosted app store. It is built around providing you with a catalog of apps that are familiar to most of us. These include things like Jellyfin, Nextcloud, Vaultwarden, and Open WebUI to name just a few. With the project, it documents things like configurable environment variables, multiple deployments, and a browser interface for managing your apps spun up in Podman.

Also, the app developer makes a point that this is not an “operating system” like many of the solutions are that do similar things (Umbrel and other “home lab” operating systems). The developer has built Yantr as an “app” and not an “OS”. So, your host stays untouched with this approach.

Yantr architecture for rootless podman containers running on top of your host
Yantr architecture for rootless podman containers running on top of your host

I think this architecture will appeal to most as in the home lab, most of us already have our hypervisor configured and a virtualization environment that is the platform we use to spin up other applications. So, putting another OS on top of a VM that is meant to be that “platform” so to speak is a bit redundant.

Instead, most of us need what this is trying to provide I think in an “app catalog” that helps you discover, pick, and deploy applications for our Podman environments.

Why rootless Podman interests me

This is probably one of the biggest reasons that I think most start looking at Podman seriously. It is because Podman runs as a rootless architecture, under a regular user account. It has a daemonless design. It also integrates natively with the Linux systemd construct to make it super familiar to those already familiar with systemd.

Podman provides a container command line that will look familiar to Docker users, and many operations can run under a regular user account. Its daemonless design and support for systemd integration make it worth exploring for Linux servers.

Podman rootless architecture compared to docker with yantr providing app catalog
Podman rootless architecture compared to docker with yantr providing app catalog

So, this is really appealing to have an application environment that doesn’t need many privileges at all. Most of us probably don’t want to have a container management context that shares a privileged account on the host. But that is often what situation we are in with Docker. This doesn’t mean I would automatically start migrating everything off Docker to Podman, but it is a good point to understand.

Yantr fits into this as I see it as a possible way to make a separate Podman environment useful to home lab environments very quickly. The catalog helps to lower the amount of work you have to do to get things setup. And, then, the command line continues to be there if you need to investigate something.

Where I am running this in relation to Proxmox

This is not something that I would install on your Proxmox host. Rather, this is something that you would install on a dedicated Linux VM on Proxmox, similar to your Docker hosts that you run. I would probably pick Ubuntu or vanilla Debian as my Linux OS of choice.

Also, it allows you if running it in a VM in Proxmox to have access to snapshots which are super powerful when it comes to testing, learning, and “rinse and repeat” operations. VMs also give you a clear boundary for testing. You can back it up, restore it, and experiment with various operating systems without affecting anything else.

You can also create a dedicated Linux account for the environment to run under which will keep the application ownership separated from other files and resources.

Installing Yantr

On the project page, it documents an installation script that configures rootless Podman and systemd Quadlet in one fell swoop. However, there is also a manual container deployment as well you can do if you already have Podman installed, which is my case.

For the fully automated install of Podman and Quadlet configuration, you can run the provided script. Here I am downloading it first. As a note, this is not the approach I used on my host since I already had Podman installed.

curl -fsSL https://yantr.org/install.sh -o yantr-install.sh
less yantr-install.sh
bash yantr-install.sh

After installation, you can check the version of the Podman engine:

podman --version
podman info
podman ps -a

If you already have Podman up and running on a host, the documentation also gives you the manual command to get Yantr up and running. This is the approach that I am using:

podman run -d \
  --name yantr \
  --network host \
  --security-opt label=disable \
  -v "${XDG_RUNTIME_DIR:-/run/user/$(id -u)}/podman/podman.sock:/run/podman/podman.sock" \
  -v yantr_data:/data:z \
  ghcr.io/besoeasy/yantr:latest
Running yantr with podman
Running yantr with podman

This command assumes the user socket is available. The manual container launch also does not replace a complete boot and service management configuration.

I would then browse to:

http://YOUR-VM-IP:5252

Once you browse out to the web interface you will see the initial setup for your authentication. It asks for a password and a PIN code:

Setup screen for your password and pin
Setup screen for your password and pin

Enter the password and PIN code:

Setting the password and pin
Setting the password and pin

It will then have you confirm it:

Confirming the password and pin

Then it will display your generated Public Key. Click Create Account.

Generated public key for yantr
Generated public key for yantr

After getting the authentication configured, you will be taken to the Yantr dashboard.

Viewing the yantr dashboard for the first time
Viewing the yantr dashboard for the first time

Browsing the app catalog

Yantr has a lot of really good apps that are part of its catalog by default. At the time of this writing, it has 163 apps in the catalog.

Viewing the yantr app catalog
Viewing the yantr app catalog

Here is the app catalog in light mode.

Viewing the app catalog in light mode
Viewing the app catalog in light mode

Here is a view of the side panel on the apps screen that I captured. Here you can see the total number of apps that are available at the time of writing. Also, I like how they have these automatically split up into the relevant categories to make finding the types of tools you are looking for much easier.

Total number of apps and categories of apps in yantr
Total number of apps and categories of apps in yantr

Temporary apps

One of the cool features that I noticed with Yantr is the ability to have an app setup as temporary. In other words, you can have Yantr automatically delete the application when the time period you configure has expired. I thought this was a really cool feature.

The temporary install flag in yantr
The temporary install flag in yantr

Below, you can see when installing an app, if you click the temporary install option, there is a drop down

Installing an app with a temporary install and seeing the expires after flag
Installing an app with a temporary install and seeing the expires after flag

Below, you can see the Obsidian stack running that was provisioned by Yantr.

Podman stack running obsidian with yantr
Podman stack running obsidian with yantr

Often, I will spin up Docker apps in the home lab and forget about them after I have tested them for a couple of days and then leave them up and running for months. This is a great way to make sure you have some automated self-cleanup happen after the fact.

Rootless does not make the management interface totally harmless

Keep in mind that just because Podman containers are rootless, it doesn’t mean there aren’t security considerations. Yantr has access to the Podman API socket. According to the Podman documentation, when you have API access this allows arbitrary code execution as the user that is running the API. A rootless socket will still allow quite a bit of control over the user’s environment.

Podman’s documentation states that API access permits arbitrary code execution as the user running the API. A rootless socket therefore still grants substantial control over that user’s environment. Make sure you use a dedicated account that has restricted management access. I would treat the interface as an administrator tool, use a strong password, etc.

Just don’t assume when you hear that rootless is a promise that vulnerabilities no longer affect you. That isn’t the case.

Built-in Cloudflare Tunnel

Also, a neat feature is that you can self-host any type of web resource that you run on a Podman container with the built-in Cloudflare Tunnel functionality it offers. Of source, the nice thing about this architecture is it means no port-forwarding, no dynamic DNS, and no public IP needs to be exposed to the Internet.

Cloudflare tunnel built into your yantr dashboard
Cloudflare tunnel built into your yantr dashboard

Backing this up

So before you move your critical data into any platform, you want to be sure you understand how you get your data back if something bad happens. Can you do that without the management interface? The cool thing with podman if you grab a backup of your host with the data mounts on the podman host, you should have a backup of your data.

But, definitely get a good inventory of the following that will be a good starting point:

podman volume ls
podman volume inspect yantr_data
podman inspect yantr

Is this free licensing?

One of the details with the project is that Yantr’s license is a PolyForm Noncommercial license. Personal and hobby use are permitted under its terms while you can’t use it for commercial use. Which this should be fine for most home lab usage.

Wrapping up

The Yantr project is pretty interesting from what I saw in my test environment. It gives you a really nice dashboard to be able to manage your Podman containers, see what they are doing, have visibility over your host, and do things like install temporary applications that auto-delete themselves after the set amount of time. What about you? Have you found something like this for Podman? What do you use?

Google
Add as a preferred source on Google

Google is updating how articles are shown. Don’t miss our leading home lab and tech content, written by humans, by setting Virtualization Howto as a preferred source.

About The Author

Brandon Lee

Brandon Lee

Brandon Lee is the Senior Writer, Engineer and owner at Virtualizationhowto.com, and a 7-time VMware vExpert, with over two decades of experience in Information Technology. Having worked for numerous Fortune 500 companies as well as in various industries, He has extensive experience in various IT segments and is a strong advocate for open source technologies. Brandon holds many industry certifications, loves the outdoors and spending time with family. Also, he goes through the effort of testing and troubleshooting issues, so you don't have to.

0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted