3 ms·
Docker containers aren't safe enough to run untrusted code, there are privilege escalation vulnerabilities reported fairly often.
by kondu 9mo ago
Docker containers aren't safe enough to run untrusted code, there are privilege escalation vulnerabilities reported fairly often.
- AlexCoventry 9mo agoI don't think bubblewrap is any better in that regard.
- exceptione 9mo agobwrap just works in rootless mode and doesn't tamper with your firewall.
- purplehat_ 9mo agoWhy do you say that? Bubblewrap is a it's a very minimal setuid binary. It's 4000 lines of C but essentially all it does is parse your flags ask the kernel to do the sandboxing (drop capabilities, change namespaces) for it. You do have to do cgroups yourself, though. It's very small and auditable compared to docker and I'd say it's safer. If you want something with a bit more features but not as complex as docker, I think the usual choices are podman or firejail.
- AlexCoventry 8mo agoThanks for the pushback, I will take a look.
- curt15 9mo agoThe common wisdom used to be that containers are not a security boundary. Is that still the case?