4 ms·
I am aware, thank you :). I responded to a sibling dupe-comment over here [1]. To summarize, in my experience there is immense value to having basic shell tool
by xmodem 4mo ago
I am aware, thank you :). I responded to a sibling dupe-comment over here [1].
To summarize, in my experience there is immense value to having basic shell tools available in the environment where you need them with zero extra friction. Stripping those out provides a security benefit only in specific nebulous and niche scenarios.
1: https://news.ycombinator.com/item?id=48561605 https://news.ycombinator.com/item?id=48561605
- fc417fc802 4mo ago> in my experience there is immense value to having basic shell tools available in the environment where you need them with zero extra friction I agree, however assuming you maintain a chroot for debugging this can be accomplished with a shell command that takes a single argument to target a running container by name. Your linked comment suggests being limited to kubernates but nsenter and a chroot are entirely runtime agnostic.