2 ms·
> should be foolproof by design. I think this is a core reason why containers have such a horrible security track record. They weren't made by design. One of
by eyberg 1y ago
> should be foolproof by design.
I think this is a core reason why containers have such a horrible security track record.
They weren't made by design.
One of the large problems is that there is no "create_container(2)". There are 8? different namespaces in conjunction with cgroups that make up "containers" and they are infinitely configurable. This is problematic and a core reason why we see container escapes almost every other month. Just look at user namespaces - some people use them and some people don't, but it was just a few months ago when multiple bypasses were published for them.