3 ms·
Securing docker, with it's weird iptables shenanigans is a nightmare. I prefer to use rootless podman, and also avoid exposing ports (by using internal routing
by jck 4y ago
Securing docker, with it's weird iptables shenanigans is a nightmare. I prefer to use rootless podman, and also avoid exposing ports (by using internal routing and if needed, a reverse proxy with only one published port)
- 2OEH8eoCRo0 4y agoSame here. Are there even legit reasons to not run all containers rootless? I run rootless everything, as well as things that need privileged ports. The design choices by the Docker team are just baffling.
- withinboredom 4y agoI believe, at the time, setting up a container required root. As in the kernel didn't expose the right pieces for a non-root user to ever dream of starting a container.
- BeefySwain 4y agoYeah it's nuts. The best solution I've found is some kind of cloud firewall, whether that be an off the self service that you use with whatever cloud provider you are using, or rolling your own by routing all traffic through another host that doesn't have Docker nuking all your firewall rules every time it restarts.
- deleted 4y ago[deleted]
- iasay 4y agoThis. You need a last resort security control against stuff like this anyway. Even an automation failure or misunderstanding of a ruleset can leave you exposed. Security must be layered.
- notimetorelax 4y agoTo be fair either in the cloud or on premise, firewall is a must. It’s just one of the layers of security.
- jwitthuhn 4y agoYeah this got me the first time I was using docker as well. I wanted my app server to only listen locally and configured it like that, then Docker helpfully punched a hole in my firewall so anything could talk to it. Agreed that podman has been a great experience in comparison.
- Spivak 4y agoPodman and Docker require the exact same shenanigans except in the one specific case using slirp4netns (rootless) in Podman or RootlessKit in Docker which requires using a tap device and an entire usemode networking stack. It's a neat trick for development environments but for real traffic you'll still have to actually do the iptables BS.
- jck 4y agoPodman 4 rootless uses a different network stack: https://www.redhat.com/sysadmin/podman-new-network-stack https://www.redhat.com/sysadmin/podman-new-network-stack It is performant enough for my usecase: services used by me and a few friends. I don't use the root mode, but I was under the impression it doesn't have the same well known docker issue where it exposes everything on the public interface(and using a firewall on top of it is complicated)