2 ms·
Here is one thing I have trouble understanding, despite working in cybersecurity. If I run a VM, I have to harden that VM. If I run a Docker container on top o
by Bucephalus355 8y ago
Here is one thing I have trouble understanding, despite working in cybersecurity.
If I run a VM, I have to harden that VM. If I run a Docker container on top of that, I now have to harden the Docker container as well. This is more work, and a greater “surface area” of attack.
Forgive my ignorance, but do most ppl run Docker through managed PaaS services now, so that they don’t have to worry about the double work of hardening the VM? That’s the only way I see it making sense long-term, where the Cloud providers manage the physical infrastructure like they do now as well as the EC2 / IaaS later.
- cookiecaper 8y agoMost people just assume that Docker is a magic box that solves all of their problems. They build Dockerfiles that depend on a grotesque cascade of hardly-vetted parent images, because then their Dockerfile is "only three lines! Ha! Take that, old guys!" If people had been asking any of the basic system engineering and security questions, we wouldn't be talking about this, or to be frank, most of the stuff that passes for "DevOps" these days.
- majewsky 8y agoOur team uses Docker containers more as a deployment strategy than as a sandbox. In conjunction with an orchestrator like Kubernetes, we get a standard way of deployment, horizontal scaling, update handling, TLS termination, etc. that works the same for every service under our reign. And it's very malleable: You have a certain amount of isolation that makes each individual service easier to handle, but you can still get through to the kernel by giving the container the appropriate privileges.