I can only speculate, because I don't use podman. With unprivileged LXC containers, it works for me under the condition that the user's token does not use a PAG but is bound to the user id only.
So, my speculation would be that apptainer is able to run inside an established PAG and podman is not. –Michael _______________________________________________ OpenAFS-info mailing list OpenAFS-info@openafs.org https://lists.openafs.org/mailman/listinfo/openafs-info