4 ms·
Well that looks very nice. For the security experts among us, would containers using root as their user be safe running on gVisor? That would save a lot of pa
by cfontes 8y ago
Well that looks very nice.
For the security experts among us, would containers using root as their user be safe running on gVisor?
That would save a lot of pain because of some super annoying bugs like this:
https://github.com/moby/moby/issues/6119 https://github.com/moby/moby/issues/6119
https://github.com/moby/moby/issues/5505 https://github.com/moby/moby/issues/5505
- cpuguy83 8y agoThere is a "--chown" flag on copy/add these days.
- ithkuil 8y agoIf it's not safe then it wouldn't be a proper sandbox I'm the first place. The goal is to intercept all system calls and reimplement them in a lightweight kernel that talks with the host kernel only via a minimal 9p based protocol. I.e. there is never a direct syscall being served by the host kernel on behalf of a process running inside the container. From what I can read in their design docs, the user id running inside the container seems completely irrelevant.
- hacknat 8y agoUser namespaces can already get you this, but this is an added layer of defence in case their are exploitable kernel vulnerabilities that could allow an attacker to break out of a container. With this runtime if you break out of the container you are in an isolated kernel. As others have pointed out though this is basically just a stripped down UML, so the performance is likely not great. Though in contexts where security is at a premium (compliance contexts for the healthcare and finance industries) it might be worth the cost.
- hugelgupf 8y agoYou can indeed safely run containers as root inside the sandbox. The UID/GID you run as is configurable.