3 ms·
Can you explain how Docker has better security then OpenShift? (asking to learn, not a challenge).
by nul_byte 10y ago
Can you explain how Docker has better security then OpenShift? (asking to learn, not a challenge).
- shykes 10y agoOff the top of my head: - End-to-end content trust with crypto signatures and verifications using Notary/TUF https://docs.docker.com/engine/security/trust/content_trust/ https://docs.docker.com/engine/security/trust/content_trust/ - Secrets management with encrypted storage and transport (https://blog.docker.com/2017/02/docker-secrets-management/ https://blog.docker.com/2017/02/docker-secrets-management/) - A vulnerability scanner that can detect vulnerabilities in arbitrary binaries without distro lock-in (ie. even if your developer built from source on a non-Red Hat distro, it will still catch vulnerabilities) https://docs.docker.com/datacenter/dtr/2.2/guides/admin/configure/set-up-vulnerability-scans/ https://docs.docker.com/datacenter/dtr/2.2/guides/admin/conf... - Secure orchestration out-of-the-box: https://docs.docker.com/engine/swarm/how-swarm-mode-works/pki/ https://docs.docker.com/engine/swarm/how-swarm-mode-works/pk... - Somewhat counter-intuitively, the default security profile is more secure in Docker than in Openshift, because the focus on "systemd everywhere" requires loosening the sandbox to allow systemd's tentacles to get through. In the past Red Hat has actually introduced CVEs in their forked version of Docker that didn't exist in the official Docker. - In Docker for AWS, Docker for Azure, Docker for Mac, Docker for Windows, we embed a specialized Linux distro that is trimmed down and locked down to the extreme, making OS surface area much much smaller than a traditional OS like Red Hat.