You can build a Dockerfile and run its image without running Podman as root. Use the same ordinary account for the build and run, and make sure that account has subordinate UID/GID ranges, usable local container storage, and working build-time networking. This walkthrough uses docker.io/library/alpine:3.20 as a concrete base-image example; it is a command path, not a report of a tested build. Podman behavior and defaults vary by release and Linux distribution, so check your installed version before applying version-specific fixes.
What rootless changes—and what it does not
Rootless Podman runs containers in a user namespace, mapping container identities to the invoking user’s host identity and subordinate UID/GID ranges. It avoids requiring a root-run Podman command for ordinary builds and runs, but it does not remove host filesystem permissions, device restrictions, SELinux policy, kernel requirements, or every resource-control limit.
As an Amazon Associate I earn from qualifying purchases.
Each account has its own Podman image and container storage. The Podman manual states: “Containers created by a non-root user are not visible to other users and are not seen or managed by Podman running as root.” A rootless image you build as your account will not appear in root’s image list, and an image pulled by root will not automatically appear in yours. The documented rootless storage location is under XDG_DATA_HOME when set, otherwise ~/.local/share/containers/storage. Podman manual: rootless mode and storage
Record the host and choose the operation
Before troubleshooting, note your Linux distribution, kernel, Podman version, and the account that will run the commands. Use podman version to identify the installed release. This matters because storage and networking defaults can change; consult documentation matching that release when a flag or default differs from the current manual.
#1 Best Overall
Decide whether you are building from a Dockerfile or trying to use an image that already exists elsewhere. Building creates an image from a recipe and a build context. Pulling retrieves an image into the current user’s store. Those operations are not interchangeable, and neither makes images visible across user accounts.
Check rootless prerequisites
Inspect the invoking user’s entries in /etc/subuid and /etc/subgid, and check that the distribution’s user-namespace helper tools, including newuidmap and newgidmap where required, are installed. Podman requires subordinate ID ranges for its normal rootless mappings. Follow your host administrator’s allocation policy rather than copying an arbitrary range from an example. Podman manual: rootless requirements
If you cannot allocate subordinate IDs—for example, in a restricted shared environment—the manual documents ignore_chown_errors as a possible single-UID compromise. Collapsing ownership can cause runtime problems; it is not the default fix for a missing mapping.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Rank #2
Build a Dockerfile as your ordinary user
Podman accepts Dockerfile syntax; its build documentation says Containerfile syntax is the same. From the directory containing the recipe and intended build context, run:
podman build -t example:local -f Dockerfile .
The final . is the build context: the files available to instructions such as COPY and ADD. Podman also recognizes the conventional filename Containerfile. If a build says a file is missing, check that it is inside the selected context and not excluded by .containerignore or .dockerignore. Podman build manual
For a concrete example, a recipe can start with the public Alpine image tag docker.io/library/alpine:3.20. A Dockerfile that only selects that base image is:
FROM docker.io/library/alpine:3.20
Save it as Dockerfile in an otherwise empty working directory, then run the build command above as your regular account. This demonstrates the build path without implying that the tag, recipe, or result was independently tested here. For a real application, use its actual Dockerfile and build context instead of substituting this minimal example.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Verify and run the image under the same account
Still as the account that performed the build, verify the image and start a disposable container:
podman images
podman run --rm example:local cat /etc/alpine-release
The image should be listed in that account’s store, and the command should print the release file contents from the container before it is removed. If the image is absent, first check which account ran the build or pull and whether XDG_DATA_HOME changes that account’s storage location. Avoid switching between root and non-root Podman commands during this workflow unless you are deliberately working with separate stores.
Rank #4
Fix failures by symptom
“No subuid ranges found” or user-namespace setup fails
Check the exact invoking user’s records in both /etc/subuid and /etc/subgid, including spelling and whitespace, and confirm the required mapping helper tools are available. Correct the allocations according to the system’s policy. If the values were just changed, an existing rootless pause process may still hold the previous mappings; use the migration procedure below.
An image is missing even though it was pulled
Check whether root or another account performed the pull. Run the pull, build, and run as the intended user, and inspect that user’s image list. Rootless and rootful Podman use separate storage; an image does not move between them merely because both commands use the same image name.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsOverlay storage fails, or builds use unexpectedly large amounts of disk
Check the graphroot filesystem, kernel support, selected storage driver, and whether fuse-overlayfs is installed. Rootless Podman can use fuse-overlayfs as a userspace overlay helper. The current manual says it is used automatically when installed if no user storage.conf already exists; an existing configuration may need an explicit mount-program setting. Without a usable overlay option, Podman may fall back to vfs, which uses more disk and is less performant. Do not assume one kernel-version threshold applies to every supported distribution and Podman release. Podman manual: rootless storage
Best Value
Do not place rootless graphroot storage on NFS or another distributed filesystem: this is unsupported. For an NFS-backed home directory, use local storage for graphroot as described in the Podman documentation.
A build-time download cannot resolve a host or reach a package server
A Dockerfile instruction such as RUN apt or RUN dnf needs network access and DNS during the build. Diagnose that separately from runtime networking and published ports. Check the host resolver, Podman’s build network configuration, the installed release, and which rootless network backend it uses. Current Podman documentation identifies pasta as the default rootless backend when available; older releases may have different defaults, including slirp4netns. The build manual documents DNS options for RUN steps. Podman manual · Podman build manual
A bind mount or device reports “permission denied”
Rootless execution does not grant access the host account lacks. Check host ownership and mode bits on the mounted path, whether access depends on a group the invoking user does not have, and whether SELinux labeling blocks access. For a requested device, determine whether the operation requires privileges unavailable to a rootless container. Fix the specific ownership, access, or label issue where appropriate; do not treat broad privilege escalation as a universal remedy. Rootless user-namespace mapping modes such as host, keep-id, auto, and nomap have different ownership and access effects. Choose a mode only after identifying the needed host-to-container identity behavior. Podman create manual: user namespace modes
New subordinate IDs appear to be ignored
Containers and the rootless pause process can keep the old namespace mappings active. Follow the installed release’s migration guidance; Podman documents podman system migrate as the way to stop the pause process and apply changed mappings. It can stop containers as part of the transition, so plan for interruption and check the release-specific manual before running it. Podman system migrate manual, v5.8.1
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




