โ† All RHCSA Flashcard Decks

RHCSA Containers and Podman Flashcards

7 cards from real RHCSA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 RHCSA Containers and Podman flashcards as text
  1. What is the primary security advantage of running Podman containers in rootless mode?

    Answer: Container processes run as a non-privileged user, reducing host compromise risk

    Rootless containers run as a non-root user on the host, so a container escape does not grant root access to the host system.

  2. After running 'podman generate systemd --name myapp --files', where should you place the generated unit file to enable it for a non-root user?

    Answer: ~/.config/systemd/user/

    User-level systemd units for rootless containers belong in '~/.config/systemd/user/' and are managed with 'systemctl --user'.

  3. Which command builds a container image from a Containerfile in the current directory?

    Answer: podman build -t myimage .

    'podman build -t myimage .' reads the Containerfile (or Dockerfile) in the current directory and tags the result as 'myimage'.

  4. How do you enable a user-level systemd service called 'container-myapp.service' to start at login for a non-root user?

    Answer: systemctl --user enable container-myapp.service

    'systemctl --user enable' manages services within the user's systemd instance; 'loginctl enable-linger' is also needed for start-at-boot.

  5. Which command displays real-time CPU and memory usage statistics for all running Podman containers?

    Answer: podman stats

    'podman stats' streams live resource utilization metrics (CPU, memory, network I/O) for running containers.

  6. By default, where are images stored for a rootless Podman user named 'alice'?

    Answer: /home/alice/.local/share/containers/storage/

    Rootless Podman stores images and container data in '~/.local/share/containers/storage/' within the user's home directory.

  7. What additional command must be run so a rootless user's container service starts automatically at system boot (not just at login)?

    Answer: loginctl enable-linger

    'loginctl enable-linger ' allows the user's systemd session to persist after logout, enabling services to start at boot.