4 ms·
Show HN: Traefik Docker Protector
- culpable_pickle 5y agoCan you explain why I would use this rather then just setting the docker socket to read only in the traefik container? That’s what I do currently and it works just fine. I’m unclear if there’s something this does extra that I’m overlooking?
- knrdl 5y agoYou mean mounting as "/var/run/docker.sock:/var/run/docker.sock:ro", right? That just prevents traefik from changing file permissions on the socket file. The socket as pipe object stays writable, so you still can send arbitrary requests to the socket. Using ro mode for socket mount is definitely a good idea, but not a solution to the security problem! See: https://stackoverflow.com/questions/40844197/what-is-the-docker-security-risk-of-var-run-docker-sock/52333163#52333163 https://stackoverflow.com/questions/40844197/what-is-the-doc... https://www.reddit.com/r/Traefik/comments/g46lhh/does_binding_the_docker_socket_in_readonly_mode/ https://www.reddit.com/r/Traefik/comments/g46lhh/does_bindin...