Apptainer creates and runs containers designed to make applications portable and reproducible, particularly on shared systems and high-performance computing clusters. It packages each container as an immutable, single-file Singularity Image Format (SIF) image for transport and sharing. Apptainer can import containers from OCI registries and aims to support pulling, running, and building most Docker Hub containers without changes. Its default security model does not give users extra host privileges inside a container. Images can be signed and verified with PGP keys, PEM keys, or X.509 certificates; encrypted containers can run without decrypted contents being written to disk. The software can expose host resources including GPUs, high-speed networks, and parallel filesystems, and supports NVIDIA CUDA, AMD ROCm, Intel Gaudi, and OCI Container Device Interface accelerators. Apptainer is free. It requires Linux to run; Windows and macOS users need a Linux virtual machine, while Windows is also listed via WSL2. Full functionality requires kernel support for FUSE and unprivileged user namespaces.
Who it is for
Apptainer suits researchers and technical teams running complex workloads on shared systems or HPC clusters. It is also relevant to organizations in academia and industry that need portable containers and access to host resources.
What is good
- Free plan and rootless operation when user namespaces are available.
- Immutable, single-file SIF images are designed for sharing.
- Supports signing and encrypted containers.
- Provides access to GPUs and other host resources.
What to know first
- Requires Linux to run; Windows and macOS need Linux environments.
- Full functionality requires FUSE and unprivileged user namespaces.
Verdict
Apptainer is built around portable, shareable containers for HPC and other shared systems. Its Linux requirement and kernel prerequisites are important to account for when planning a deployment.
Apptainer plans and pricing
All plansCompared on container engines
- Free plan
- Yes
- Rootless mode
- Yes
- Image building
- Yes
- Windows containers
- No
- Image format
- both
- Runtime interface
- other
- Supported host OS
- Linux; Windows via WSL2; macOS via Linux VM


