3 ms·
That's fair! That's a good point, and I don't mean to invalidate those situations. A part of me still feels like that's somewhat separate from a "typical" scen
by ipdashc 3y ago
That's fair! That's a good point, and I don't mean to invalidate those situations.
A part of me still feels like that's somewhat separate from a "typical" scenario where you want to harden a container that's exposed to the outside world in some way; like I said, your average container running a webapp or whatever. Nvidia Insight seems to be a performance analysis tool, so I would hope nobody is running it with untrusted input or exposing it to the Internet. (Yes, I know someone out there totally is.)
Similarly, it feels near-obvious to me that adding a privilege called "SYS_ADMIN" to a container will make it more or less equivalent to root on the host. It's not like Docker hides this info from people, last I checked it's explained pretty prominently.
You're totally right overall, it still matters, it's just something about this framing that rubs me the wrong way.