3 ms·
This is very useful for running containers in lightweight untrusted environments. I personally use this setup for my GitLab CI runners, using a mix of podman a
by RandomBK 3y ago
This is very useful for running containers in lightweight untrusted environments.
I personally use this setup for my GitLab CI runners, using a mix of podman and buildah to build containers. I can't 100% trust the container build script, so avoiding having to expose a Docker socket to that untrusted code is a critical safety layer.
- storrgie 3y agoDo you have a writeup on this configuration?