3 ms·
Unless you are using DC/OS enterprise, DC/OS is incredibly insecure by default. Any container running in the cluster has access to the full marathon API (which
by gnur 8y ago
Unless you are using DC/OS enterprise, DC/OS is incredibly insecure by default. Any container running in the cluster has access to the full marathon API (which has NO auth). So any compromised container will be able to: stop and delete everything, see all environment variables set for other containers (often contain secrets for databases or other external apis) and even start arbitrary new containers on your cluster.
So think about it, any compromise in anything you run on the cluster has the potential to access all your data.
This alone should be reason enough to never use the free DC/OS, and the enterprise offering has no public pricing information.