4 ms·
At this point there really isn’t any security difference between zones, jails, and hardened containers. That word “hardened” is the key. Zones are a primitive i
by hacknat 8y ago
At this point there really isn’t any security difference between zones, jails, and hardened containers. That word “hardened” is the key. Zones are a primitive in Illumos, containers are not a primitive in Linux, they are a collection of security features. If you use them all then you can achieve parity with Zones, but surprisingly few projects make use of all of them by default (Docker certainly doesn’t).
The main difference then is usability, which is almost always the biggest security flaw in any piece of software (that the security isn’t “on” by default or has a prohibitive learning curve for the user).
- posix_me_less 8y ago> Docker certainly doesn’t Do you think LXD gets closer to Zones in terms of security?
- hacknat 8y agoHonestly, I don’t know, but my guess is that it had some things turned off by default. Actually K8s is the most encouraging project in this regard in that it has opinions about how containers should work so they are slowly adding all the secure options by default when containers are orchestrated to the various runtimes. There are only a few features left that remain to be turned on (user namespacing being the most notable).
- technofiend 8y agoI paraphrased you by cutting down your comment, hope that's OK. >Actually K8s [...] are slowly adding all the secure options by default [...] (user namespacing being the most notable). K8's RBAC is nice, and in particular auth-delegator really helps with odd duck integration for the enterprise. But k8s is reliant on OS features to make user namespaces happen and Redhat customers are still waiting for Redhat to backport a newer version of shadow-utils [1] [2] to RHEL 7 so that user namespacing works there. Given enterprise certification and release cycles "Wait for RHEL 8" isn't really a good answer for those kind of customers. I'm not disagreeing with you, just saying some features of kubernetes aren't available everywhere. Personally I'd really like to see user namespaces come to RHEL 7 as it helps with removing or mitigating privileged access. [1] https://bugzilla.redhat.com/show_bug.cgi?id=1498628 https://bugzilla.redhat.com/show_bug.cgi?id=1498628 [2] https://access.redhat.com/solutions/3657531 https://access.redhat.com/solutions/3657531
- qlk1123 8y agoJust a weakly related comment here. When one talks about security, it's really hard for people to follow what she really means; the context has always been qualitative, but not quantitative. I found the idea "Vertical/Horizontal Attack Profile" interesting, which may help measure security when people argues different container solutions or even VMs. https://blog.hansenpartnership.com/measuring-the-horizontal-attack-profile-of-nabla-containers/ https://blog.hansenpartnership.com/measuring-the-horizontal-...