Podman is the container tool I want on Fedora, and Quadlets are the way I want it on Fedora CoreOS. A Quadlet is a systemd unit that Podman turns into a service. Reboots bring the container back. You do not leave a podman run in your shell history and call it a deployment. The posts here are the 2026 CoreOS guide that lands AdGuard Home this way, the narrower AdGuard and Pi-hole units, and the earlier beginner install that introduces Podman next to the host.
Docker still has a tag, and some of these posts wear both, because people search the tool they already know. On CoreOS I would rather you follow the Quadlet. Rootless versus root, the user the unit runs as, and the ports you publish are the details that decide whether DNS works for the LAN and whether the admin UI is reachable from the parking lot. The AdGuard post is the one that also locks that down with nftables. Read it even if you came for Pi-hole, then decide you only need one resolver.
Silverblue and Workstation can run Podman too, but the pages I send people to for virtualization and Homebrew are about rpm-ostree layering, not about a Quadlet. Do not layer a desktop stack onto the DNS host so you can 'just peek.' SSH in, journalctl the unit, and keep the GUI on a different OS. That split is the whole homelab.
Start here
- Beginner's Guide to Fedora CoreOS (with Bitwarden SSH Keys)
From Ignition to a running AdGuard Quadlet, including the SSH key the installer will trust.
- Running AdGuard Home as a Podman Quadlet on Fedora CoreOS
The unit, auto-updates, and a firewall. This is the copy I want on a host that already exists.
- Running Pi-hole as a Podman Quadlet on Fedora CoreOS
The same idea for Pi-hole. One resolver per address. Port 53 does not negotiate.
- Beginner's Guide to Fedora CoreOS
The shorter introduction, if you want the host story before the unit file.