4 ms·
Full virtualization. Docker implies a shared kernel attack surface, that's what you want to avoid.
by ethersteeds 1y ago
Full virtualization. Docker implies a shared kernel attack surface, that's what you want to avoid.
- afiori 1y agoKernel level exploits are more dangerous but also way less common, for a lot of places docker is sorta okay as a security boundary
- ta1243 1y agoIt's layers. Docker is better than nothing, but a VM is better still, and even better is docker on a dedicated VM on dedicated hardware on a dedicated network segment.
- mschuster91 1y agoThat's sacrificing an awful lot of latency cost for each transcode job though.
- ethersteeds 1y agoEach job sends a provisioning ticket to a thermal printer. 1 business day turnaround, unless we need to order more servers
- xxpor 1y agoFirecracker says it can start a VM in 125 ms, for most transcode jobs that seems like it'd be a trivial cost.
- afiori 1y agoTo make a bit of a strawman of what you are saying even better still would be an unplugged power cable as a turned off machine is (mostly) unhackable. To be more serious seurity is often in conflict with simplicity, efficiency, usability, and many other good things. A baseline level of security (and avoidance of insecurities) should be expected everywhere, docker allows many places to easily reach it and is often a good enough tradeoff for many realities.
- endre 1y agothat escalated quickly. but I agree.