3 ms·
Here's my approach: https://www.codrut.pro/snippets/docker-images-basic-ruby-setup/ https://www.codrut.pro/snippets/docker-images-basic-ruby-set... [Edit] This
by sdwolfz 6y ago
Here's my approach: https://www.codrut.pro/snippets/docker-images-basic-ruby-setup/ https://www.codrut.pro/snippets/docker-images-basic-ruby-set...
[Edit] This is what I use for local development docker images.
Note: I disagree with this article, none of the things listed are "best" practices in my opinion... more like random practices somebody prefers. Use what you like.
- kubanczyk 6y agoOP's version: > UIDs below 10,000 are a security risk on several systems, because if someone does manage to escalate privileges outside the Docker container their Docker container UID may overlap with a more privileged system user's UID granting them additional permissions. > [...] there may sometimes be reasons to not do what is described here, but if you don't know then this is probably what you should be doing. Your version: > Use what you like. > UID=1000
- sdwolfz 6y agoI should probably also mention this example is for docker images that I use for local development with a shared file mount having the same UID/GID as your host, so you don't have to `chown` all the time while developing.
- BossingAround 6y ago> more like random practices somebody prefers Surely, if "X" has posed a security flaw in the past, and "Y" achieves the same as "X" without being vulnerable to the exploits (e.g. the UID advice), then "Y" is objectively better and not a matter of style, is it not?