3 ms·
Not sure why this is relevant, but here goes: I was working on a greenfield project where containers were at the core of it. The amount of due dilligence that w
by lapser 4y ago
Not sure why this is relevant, but here goes: I was working on a greenfield project where containers were at the core of it. The amount of due dilligence that was happening was great. Containers were scanned. Configuration was sanity checked. Generally security standards were pretty high. Surprisingly there were very few security folks who didn't know what they were talking about. Contrary to other banks I've been at who don't run on containers.
Comparing that with a neobank that runs K8s, successfully might I add, who has outdated software, and only recently started investigating upgraded.
The same configuration issues you mention has nothing to do with containers, as doing an apt-get install often has the same issues. It has everything to do with people using tools they have little understanding of. I'm talking about mysql, and mongodb, not docker.
- trasz 4y agoYou used containers you built yourselves though, right? As opposed to generic ones, eg from Docker Hub?
- loriverkutya 4y agoProbably they built their containers, wrote the containerisation sysstem, wrote all the libraries they were using, wrote the operating system, the CPU microcode, designed and built all hardware parts they were using.
- lapser 4y agoYou're missing the point. The official docker containers can be configured secure or insecure. Same with in house built containers. Same with installing an application via apt/yum/pacman/what-have-you.
- trasz 4y agoYou’re missing the point. That flag doesn’t matter; what does matter is whether the team understood what’s happening inside the container, or didn’t.