Not requiring a service running in root context.
I don't think I've ever understood the distinction in this argument.
Isn't systemd exactly that, a service running in root context?
I mean yeah you can technically run podman containers by hand as a non-privileged user but nobody does that, let's be serious. Everybody uses systemd for management and autostart.
I really don't understand how running a container through docker as a non-privileged user and dropping all caps is any different from doing the same through systemd + podman.
Tons of other services do that, ssh, CUPS etc.
If anybody can explain the difference I'd appreciate it.