Podman backend
Usesandbox.backend: "podman" to select the native podman CLI directly. This is a built-in backend, not a plugin. It does not probe or select Docker, even when the docker executable is installed.
Podman reuses the existing sandbox.docker.* settings and the active native podman CLI context; it adds no separate connection configuration surface.
Rootless Podman defaults to --userns=keep-id for writable workspace mounts. A long-lived sandbox can reserve subordinate IDs and block unrelated --userns=auto workloads; remove it before starting those workloads. Set sandbox.docker.user to a nonzero numeric UID or UID:GID to control the container user. Rootless Podman rejects UID or GID 0 because Podman 4.x cannot remap namespace root while preserving workspace bind ownership; bake root-required setup into the image or use rootful Podman. Rootful Podman otherwise uses the workspace owner when available.
Host init prerequisite
OpenClaw creates Podman sandboxes with--init so orphaned tool processes are reaped. The Podman engine host needs its init executable, normally catatonit. Installing it only inside the sandbox image does not satisfy this requirement. For Podman Machine, the executable belongs inside the machine, not on the client host.
On Debian or Ubuntu, minimal installs using --no-install-recommends can omit the helper. Include it explicitly when provisioning the engine host:
lookup init binary or container-init binary not found on the host, install the helper or repair Podman’s configured init_path/helper_binaries_dir in containers.conf, then retry. Podman can resolve helpers outside PATH; a successful podman info does not prove that --init works. Keep sandboxing and --init enabled rather than bypassing this prerequisite.
Podman notes:
- Browser sandboxing is not supported by Podman; keep
sandbox.browser.enabledoff, or install Docker and selectbackend: "docker". - Local Podman engines and Podman Machine are supported. Podman Machine bind sources must be under the host home directory, which is its default shared volume. Arbitrary remote Podman connections are rejected; use the SSH backend for remote execution.
- Custom
tmpfsor bind mounts must not cover/run/podman-init; OpenClaw rejects them so sandbox cleanup continues to work.