Define once. Run anywhere.
No host daemon_
You write a TOML file. podbox turns it into an image and a set of systemd units, and from then on systemd does the rest. Nothing of podbox keeps running on your machine.
1# Grab the binary & verify2curl -fsSL https://bethropolis.github.io/podbox/install.sh | sh1# Install as a mise tool (Linux only)2mise use -g github:bethropolis/podbox1# Homebrew (Linux only)2brew install bethropolis/homebrew-tap/podbox1# Arch Linux, via AUR (binary, fast)2paru -S podbox-bin3 4# ...or build from source5paru -S podbox1# From crates.io (supports prebuilt images only)2cargo install podbox-cliNote: the crates.io build supports prebuilt images only (image_ref in your config, or podbox create ghcr.io/bethropolis/podbox:<tag>). Custom image builds need a full source build from the workspace.
1# Source install (builds CLI & guest daemon)2git clone https://github.com/bethropolis/podbox3cd podbox && scripts/install.sh # installs to ~/.local/bin1# Spin up a prebuilt Fedora container and hop in2podbox create fedora3podbox enter fedoraA container you can rebuild from a file
Your home directory stays out of it unless you ask. Everything else is written down first.
One TOML file
Image, packages, mounts and runtime in a single file you can commit. No flags to retype.
systemd runs it
Autostart, restart and socket activation come from systemd. No podbox daemon runs on your machine.
Your screen and sound
GUI apps and games work, with GPU acceleration. Wayland, PipeWire and graphics are handled for you.
Filtered D-Bus
The session bus is not handed over whole. Only the interfaces you allow reach the host.
Apps without a shared home
Export a desktop entry to your launcher or a tool to your PATH, with no home directory shared.
Fast starts
Packages are baked into the image at build time, so containers start in milliseconds.
podbox, Distrobox, or raw podman
Distrobox shares your home and gets out of the way. podbox shares nothing until you write it down.
| What | podbox | Distrobox | Raw podman |
|---|---|---|---|
| Your files | Isolated by default | Whole $HOME mounted | Manual -v flags |
| Config | One TOML file | Command-line flags | Flags every run |
| Lifecycle | systemd units | Wrapper scripts | You start it |
| Desktop bus | Filtered proxy | Whole session bus | Whole session bus |
| Screen, sound, GPU | Shared, GPU optional | Shared by default | Manual device flags |
| Alerts, clipboard | Works, no shared bus | Via the shared bus | Not supported |
| Host commands | Opt-in and filtered | distrobox-host-exec | Not supported |
| Built-in packages | Baked into the image | Reinstalled each build | n/a |
| Reproducible | Yes, from the file | Partly, image only | No |
| Runtimes | Podman only | Podman, Docker | Any |
Both projects are reasonable. Distrobox optimises for feeling like the host; podbox optimises for reproducing the same environment from a file.
How it works
Click any box to see what that part does.
podbox build / Pure Codegen Engine
A purely declarative compiler with no persistent background daemon. Parses the TOML, embeds the guest daemon binary into the container build context, writes a multi-stage Containerfile, and generates standard systemd Quadlet unit files.
- ›Pure function: TOML -> Containerfile + Quadlet units
- ›Zero memory overhead when idle; terminates upon build completion
- ›Supports prebuilt registry tags or custom multi-package baking
Build your container
Flip a switch, see the podbox.toml and the .container unit it produces. Studio has everything else.
Used for the container, its folder and its systemd unit.
Baked into the image, separated by commas.
# podbox.toml for dev-box[image]name = "dev-box"base = "fedora:44" [image.packages]install = ["neovim", "ripgrep", "git", "fish"] [container]name = "dev-box"home = "~/containers/dev-box" [integration]wayland = trueaudio = truegpu = "auto"dbus = true [integration.xdg_dirs]projects = { enabled = true, read_write = true } [lifecycle]quadlet = trueon_stop = "keep"The commands you will actually use
Build the image
# Build current directory's podbox.tomlpodbox build . # Or build from a specific configpodbox build ~/configs/fedora.tomlGet in, or run one command
# Start container (if stopped) and enter shellpodbox enter fedora # Or run a command directly inside without enteringpodbox exec fedora -- cargo checkPut an app on your desktop
# Export desktop application (.desktop file)podbox export app code # Export CLI tool to ~/.local/bin on hostpodbox export bin rgSee what it is doing
# Check systemd user service statussystemctl --user status podbox-fedora.service # View container logs via journaldjournalctl --user -u podbox-fedora.service -fBefore you start
What you'll need
- ✓Podman 5.5 or newer (5.6+ for SSH agent passthrough)
- ✓A systemd user session
- ✓Linux with a Wayland compositor (X11 apps work via Xwayland)
- optional
xdg-dbus-proxy, for filtered D-Bus access
Something not working?
Run podbox doctor first. It catches most setup problems on its own, and the troubleshooting guide goes deeper.
podbox doctor