4 ms·
It's also possible to run a web browser in a docker container which can be interacted with on the host OS. This avoids the permissions issues with solutions lik
by Thriptic 6y ago
It's also possible to run a web browser in a docker container which can be interacted with on the host OS. This avoids the permissions issues with solutions like firejail:
https://blog.jessfraz.com/post/docker-containers-on-the-desktop/ https://blog.jessfraz.com/post/docker-containers-on-the-desk...
- willglynn 6y ago`docker` implies access to the Docker daemon, which is not an improvement over the setuid binaries anderspitman found distasteful. https://docs.docker.com/engine/security/security/#docker-daemon-attack-surface https://docs.docker.com/engine/security/security/#docker-dae...
- lxdquestion 6y agoGenuine question, would LXD be any better? I'm not an expert in containerization but I find it really interesting. There are some blogs that talk about how to do this: https://blog.simos.info/how-to-easily-run-graphics-accelerated-gui-apps-in-lxd-containers-on-your-ubuntu-desktop/ https://blog.simos.info/how-to-easily-run-graphics-accelerat...
- sadfklsjlkjwt 6y agoIf it runs in the same Xwindows session no.
- deleted 6y ago[deleted]
- folmar 6y agoIf your docker is in fact podman your rootless might be attainable.
- sadfklsjlkjwt 6y agoPlease don't suggest using Docker to sandbox a GUI app.
- xorcist 6y agoThat's not a good idea. The attack surface of docker is enormous compared to firejail.