4 ms·
This has been a known Docker "feature" since the beginning, nothing new here. This pattern is used to configure host machines by some tools.
by throwawaypath 4mo ago
This has been a known Docker "feature" since the beginning, nothing new here. This pattern is used to configure host machines by some tools.
- canadaduane 4mo agoIsn't this one of the main improvements that Podman has over Docker?
- 0xbadcafebee 4mo agoNo, Docker can run rootless too
- righthand 4mo agoThis was not always true and running rootless has been a benefit of Podman for a long time. Docker also does not run rootless by default afaik, thus making the attack surface greater by default. The other main improvement of Podman over Docker is that Podman is daemonless and therefor is incredibly lightweight and portable.
- Zopieux 4mo agoI don't understand why anyone still uses docker.
- Kaliboy 4mo agoInertia I guess... We try. I managed to remove it everywhere in our stack in CI and such but in dev everyone is used to docker build. And I don't have the energy for the team meeting to discuss a change. And honestly docker compose has been ridiculously stable for us. 2+ services on seperate servers behind haproxy has been as stable as our Kubernetes Cluster for a fraction of the (intellectual) cost.
- 0xbadcafebee 4mo agoBecause Docker works better
- vdfs 4mo agoDaemonless also make it a nightmare to run especially compose like setup, you have to do some weird systemd stuff
- KAMSPioneer 4mo ago> weird systemd stuff I mean, if you have zero experience with systemd, then yes. By contrast, if you've ever worked with any systemd unit files at all, then all the "systemd stuff" will be very familiar. Which, if you're doing sysadmin type things on almost (e.g. not Alpine) any mainstream Linux distro in 2026, you should expect to encounter systemd unit files in your day-to-day.
- 0xbadcafebee 4mo agoI'm sorry but this is all just apologism/excuses. Docker's had rootless mode for 7 years. The attack surface is the local system, which always has a privilege escalation vuln of some kind, so Docker isn't a game-changer. And lightweight? I have never heard someone say "that Docker daemon is hogging all my resources".
- yjftsjthsd-h 4mo agoThis, and the charming fact that it bypasses your firewall.
- pqdbr 4mo agoLike the known Docker "feature" that it completely bypasses UFW and unless your ports look like "- 127.0.0.1:PORT:PORT" (and many of the examples use "-PORT:PORT") you expose everything to the internet?
- Root_Denied 4mo agoMy understanding is that docker will expose the ports to the host machine's network interfaces, which is a crucial difference. For my home server running docker that means exposed to the LAN, but not the WAN unless I add in a port forwarding rule on my router. Similarly in an enterprise environment you would be exposing the port on whatever VLAN the host is connected to, which hopefully doesn't have directly transit to the open internet. Anything you're running on the perimeter with open access to the internet in an enterprise environment probably (hopefully) isn't running docker containers without some additional config and protections.
- itintheory 4mo agoI was thinking along similar lines to what you've suggested here, but then I considered how many VPS might be configured by folks following some random web tutorial, to set up their LAMP stack (or whatever), that end up doing something like what was described.