4 ms·
Docker has a concept of layered images where only the top-layer is writable. The layer above the "scratch"[1] image usually contain all the files of the base im
by lmuench 6y ago
Docker has a concept of layered images where only the top-layer is writable. The layer above the "scratch"[1] image usually contain all the files of the base images OS and that's what you set your root directory to. The writable layer disappears when the container is stopped. If you mount your DIY container into /tmp for example, the process running inside your container won't be able to access any OS functionality. You couldn't run a web server in such a container for instance. On the other hand, whatever your containerized process writes into the mounted part of your hard disk won't disappear when the container stops. Because of that, I wouldn't run untrusted code in it.
[1] https://hub.docker.com/_/scratch https://hub.docker.com/_/scratch
- rantwasp 6y agothis is the file system not docker itself. you can get the overlay behavior without any docker
- lmuench 6y agoCan you point me to some online resources? I'd like to learn more about this.
- mehrdadn 6y agoI'm not sure if this is what the parent is referring to but there are overlayfs and unionfs in Ubuntu for example.
- rantwasp 6y agostart with: https://windsock.io/the-overlay-filesystem/ https://windsock.io/the-overlay-filesystem/ after that read more about overlay, overlay fs, for historical reasons aufs.
- throwaway8941 6y agohttps://lwn.net/Articles/324291/ https://lwn.net/Articles/324291/ https://lwn.net/Articles/325369/ https://lwn.net/Articles/325369/ https://lwn.net/Articles/327738/ https://lwn.net/Articles/327738/
- rantwasp 6y agonice. thank you
- mehrdadn 6y agoI see, thanks. It's just a matter of preparing the directory before and cleaning it up afterward though, right? Not a security hole exactly?
- lmuench 6y agoCorrect.