3 ms·
The integration of Traefik with the Docker daemon should mainly just be used while developing (imho). Once you get to acceptance / production environments, yo
by gnur 8y ago
The integration of Traefik with the Docker daemon should mainly just be used while developing (imho).
Once you get to acceptance / production environments, you are very unlikely to run plain docker containers, if you use kubernetes you interface Traefik with the kubernetes api itself, and the service account you create for Traefik can be (and should be) completely read only.
Same for Docker Swarm, Marathon, Consul and AWS ECS.
So no, Traefik is not the big security problem you make it out to be.
Sorry to be so harsh, but Traefik is one of the most amazin pieces of software I have come across in the last years that has seriously made my life much easier.
- jakobegger 8y agoIf software has an insecure mode "just for development" that absolutely shouldn't be used in production, you can be certain that a large fraction of developers will use that in production nevertheless. Security today doesn't mean that you are safe if you do everything according to best practices and follow the docs. Modern Security includes making sure that default settings are safe, and that it should be impossible or hard to set up the software in an insecure manner. If you make it easy to shoot yourself in the foot, that's what people will do.
- raverbashing 8y ago> If you make it easy to shoot yourself in the foot, that's what people will do. Yes they will. Just repeating it here because it bears repeating. Yes, they don't care. And yes, there will be an attacker trying to exploit it.
- heavenlyblue 8y agoWell, then let's allow the evolution take it's place.
- gnur 8y agoTo be fair, this is a limitation of Docker, there is nothing Traefik can do about it.
- nemothekid 8y agoIf you use Traefik with Docker Swarm, the official docs[1] recommend you mount /var/run/docker.sock. Sure its not a problem if you use k8s, mesos, consul, or any of the other schedulers, but the security gap is still there. [1] https://docs.traefik.io/user-guide/swarm-mode/#deploy-trfik https://docs.traefik.io/user-guide/swarm-mode/#deploy-trfik