# Podman on guix (rootless-podman-service-type)

**URL:** <https://forum.systemcrafters.net/t/podman-on-guix-rootless-podman-service-type/1496>\
**Category:** Guix\
**Created:** [March 17, 2025, 10:55am UTC](https://forum.systemcrafters.net/t/podman-on-guix-rootless-podman-service-type/1496 "2025-03-17T10:55:22Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![cinquiee](https://avatars.discourse-cdn.com/v4/letter/c/9fc348/32.png) [@cinquiee](https://forum.systemcrafters.net/u/cinquiee)\
**Post date:** [March 17, 2025, 10:55am UTC](https://forum.systemcrafters.net/t/podman-on-guix-rootless-podman-service-type/1496/1 "2025-03-17T10:55:22Z")

</div>

i found a [couple](https://gooseandquill.blog/posts/install-rootless-podman-on-guix.html) [tutorials](https://www.youtube.com/watch?v=CC7t7foYkko) for podman on guix from before [rootless-podman-service-type](https://forum.systemcrafters.net/t/rootless-podman-support-coming-to-the-guix-system/935) existed

but how do we setup podman now that it does exist? ive tried finding documentation for rootless-podman-service-type but don’t think it has been created yet, do i just copy whats at the top of [the issue thread](https://issues.guix.gnu.org/72740)?

if so, whats `small-guix`, and why’s `(service iptables-service-type)` needed?

EDIT: nevermind, i _just_ found [a manual page](https://guix.gnu.org/manual/devel/en/guix.html#index-Rootless-Podman) that wasnt coming up with search engine, ill try that out first!

---

<div class="post-metadata">

**Author:** ![daviwil](https://yyz1.discourse-cdn.com/flex029/user_avatar/forum.systemcrafters.net/daviwil/32/1_2.png) [@daviwil](https://forum.systemcrafters.net/u/daviwil)\
**Post date:** [March 17, 2025, 11:52am UTC](https://forum.systemcrafters.net/t/podman-on-guix-rootless-podman-service-type/1496/2 "2025-03-17T11:52:46Z")

</div>

This is really cool, I had not seen `rootless-podman-service-type` yet. Thanks for pointing it out!

---

<div class="post-metadata">

**Author:** ![cinquiee](https://avatars.discourse-cdn.com/v4/letter/c/9fc348/32.png) [@cinquiee](https://forum.systemcrafters.net/u/cinquiee)\
**Post date:** [March 17, 2025, 2:09pm UTC](https://forum.systemcrafters.net/t/podman-on-guix-rootless-podman-service-type/1496/3 "2025-03-17T14:09:25Z")

</div>

okay now i get `error: subid-range: unbound variable` so im trying to figure out that…

---

<div class="post-metadata">

**Author:** ![paul](https://avatars.discourse-cdn.com/v4/letter/p/bbe5ce/32.png) [@paul](https://forum.systemcrafters.net/u/paul)\
**Post date:** [March 17, 2025, 7:41pm UTC](https://forum.systemcrafters.net/t/podman-on-guix-rootless-podman-service-type/1496/4 "2025-03-17T19:41:49Z")

</div>

> whats `small-guix`

`small-guix` is my personal channel, where [I test implementations before sending them to Guix mainline](https://codeberg.org/fishinthecalculator/small-guix)

> why’s `(service iptables-service-type)` needed?

An iptables basic config is required for podman to share ports , docker does this on its own under the hood. the `rootless-podman-service-type` just explicitates this dependency.

> okay now i get `error: subid-range: unbound variable` so im trying to figure out that…

that is probably because you need to import `(gnu system accounts)` . this is [stated in the `subids-service-type` documentation](https://guix.gnu.org/manual/devel/en/guix.html#subordinate_002duser_002dgroup_002dids), but I forgot to add it also to the podman one. I’ll send a patch if I remember, otherwise feel free to do so yourself if you want

---

<div class="post-metadata">

**Author:** ![daviwil](https://yyz1.discourse-cdn.com/flex029/user_avatar/forum.systemcrafters.net/daviwil/32/1_2.png) [@daviwil](https://forum.systemcrafters.net/u/daviwil)\
**Post date:** [March 17, 2025, 7:50pm UTC](https://forum.systemcrafters.net/t/podman-on-guix-rootless-podman-service-type/1496/5 "2025-03-17T19:50:32Z")

</div>

Nice to see you here @paul, thanks for putting this service together!

---

<div class="post-metadata">

**Author:** ![wegei8](https://avatars.discourse-cdn.com/v4/letter/w/53a042/32.png) [@wegei8](https://forum.systemcrafters.net/u/wegei8)\
**Post date:** [July 31, 2025, 4:24am UTC](https://forum.systemcrafters.net/t/podman-on-guix-rootless-podman-service-type/1496/6 "2025-07-31T04:24:35Z")

</div>

Just in case anyone misses the link to the solution (I missed it), here it is:

Manual for `rootless-podman-service-type`: [GNU Guix Reference Manual](https://guix.gnu.org/manual/devel/en/guix.html#index-Rootless-Podman)

Which provides this example:

```scheme
(use-service-modules containers networking …)
(use-modules (gnu system accounts)) ;for 'subid-range'

(operating-system
  ;; …
  (users (cons (user-account
                (name "alice")
                (group "users")

                ;; Adding the account to the "cgroup" group
                ;; makes it possible to run podman commands.
                (supplementary-groups '("cgroup" "wheel"
                                        "audio" "video")))
               %base-user-accounts))
  (services
    (append (list (service iptables-service-type)
                  (service rootless-podman-service-type
                           (rootless-podman-configuration
                             (subgids
                               (list (subid-range (name "alice"))))
                             (subuids
                               (list (subid-range (name "alice")))))))
            %base-services)))

```
