4 ms·
> Anyway, what I really wanted to complain a bit about is the realm of software intended to be run on servers. Okay. > I'm not sure that Docker has saved me m
by leonheld 3y ago
> Anyway, what I really wanted to complain a bit about is the realm of software intended to be run on servers.
Okay.
> I'm not sure that Docker has saved me more hours than it's cost
I'm not sure what's the alternative for servers here. Containers have certainly saved me of a lot of headache and created very little overhead. N=1 (as it seems to be the OP).
> The problem is the use of Docker as a lowest common denominator [...] approach to distributing software to end users.
Isn't the issue specific for server use? Are you running random images from the internet on your servers?
> In the worst case, some Docker images provide no documentation at all
Well, in the same vein as my last comment, Docker is not a silver bullet for everything. You still have to take care of what you're actually running.
Honestly the discussion is valid, but I think the OP aimed at "the current state of things" and hit a very valuable tool that doesn't deserve some of the targeted cristicism I read here.
edit: my two cents for those who cannot bother and expect just because it's a container, everything will magically be solved: use official images and those from Bitnami. There, you're set.
- viraptor 3y ago> I'm not sure what's the alternative for servers here. Nixos/nixpkgs: isolated dependencies / services, easy to override if needed, configs follow relatively consistent pattern (main options exposed, others can be passed as text), service files can do isolation by whitelisting paths without going full-blown self-contained-os container. > Are you running random images from the internet on your servers? Many home server users do this. In business use, unless you invest lots of time into this, a part of your services is still effectively a random image from the internet. > and those from Bitnami Yes, that's a random image from the internet.
- blackoil 3y ago> Yes, that's a random image from the internet. By that definition, you are running it on a random OS, random processor with some random network infra.
- viraptor 3y agoKinda. It depends what your risk tolerance is. But seriously, what's your business relationship to bitnami? What are the guarantees about keeping those images up to date? What are the guarantees about the feature set provided? How long will the specific image be available publicly/free? Is the base system guaranteed to stay the same? What about architecture support?
- TeMPOraL 3y agoI mostly agree with GGP, but GP has a point. I'm a semi-frequent users of Docker at work and personally, and I still don't know what the fuck "Bitnami" is. I'm gonna guess now (and check later) they're probably some corporate body that fell out of whatever kerfuffle happened with Docker licensing a year or so ago; but otherwise, "Bitnami" sounds to me like "Bincrafters" from Conan/C++ world - no fucking clue who they are (the name doesn't help), but everyone sure likes to depend on what sounds like a random third party.
- patrick451 3y agoIt's always been surprising to me how little people seem to care about the provenance of their images. It's even more surprising that infosec isn't forcing developing to start their images `FROM scratch`.
- w-ll 3y agoAre you compiling you os distro's `FROM scratch`? Ther's always a certin level of trust, and for many, docker containers are just as trusty as distros from trusty orgs or volunteers.
- patrick451 3y ago> Are you compiling you os distro's `FROM scratch`? As a matter of fact, yes.
- rnimmer 3y agoThere once was a man named Terry Davis...
- w-ll 3y agoI imagine anyone with a BA in CS has wrote a OS from scratch. How many systems on chips are in a moderen computer, not the main system and cpu, but every little chip and controller, the boot system, every board seems to have a little OS. In regards to security, its all about analysing risk and trade-offs. For me using containers from known vendors is a risk im willing to take.
- viraptor 3y ago> I imagine anyone with a BA in CS has wrote a OS from scratch. Not even close. Very few courses require anything that advanced and only some of those are non-optional.
- jdwithit 3y agoOr for a less out-there example, Ken Thompson's classic "Reflections on Trusting Trust". At some point unless you are literally producing all of the hardware and software yourself you have to trust someone. The challenge is figuring out where that line of acceptable risk lies for you. It's going to be very different for an indie game dev vs a FinTech company vs the US DoD.
- alexey-salmin 3y ago> Isn't the issue specific for server use? Are you running random images from the internet on your servers? Well exactly, there's what the author is writing about. The whole article is dedicated to the problem of Docker being used as a distribution method, that is as a replacement for say Debian package. So in order to use that software you need to run a Docker image from the internet which is open poorly made and incompatible with your infrastructure. Had a package been available you'd simply do "apt-get install" inside your own image built with your infrastructure in mind.
- pointlessone 3y ago> use official images and those from Bitnami In other words, random images from the internet. > You still have to take care of what you’re actually running. This is the central thesis of OP, though. Pre-made/official images are not very good and docker in general doesn’t provide any means to improve/control quality.