4 ms·
> "let's just use docker, then we don't have to think about complicated linux things like priviledges and permissions" Honestly, that's fine. What more do you
by staticassertion 5y ago
> "let's just use docker, then we don't have to think about complicated linux things like priviledges and permissions"
Honestly, that's fine. What more do you want? For developers to roll their own SELinux and Apparmor profiles? For them to manually implement seccomp filtering? No one does that.
The reality is that no one is choosing between "containers or some other approach", they're choosing between "containers or nothing".
- danuker 5y agoHopefully they aren't choosing containers between "containers + insecure app" or "no containers + secure app", thinking containers will secure the app.
- magicalhippo 5y agoWho does that? I have specific apps to run, the choice is to deploy them bare or in containers.
- atoav 5y agoAs a user yes, as a developer many people who would have to think long and hard about when to use which linux user with which priviledges, when to drop them outside of an container will just use root for everything within the container out of an false sense of security. Software security always works in layers and if your only layer is the container, good luck with that.
- deleted 5y ago[deleted]