3 ms·
I heard containers aren't very secure and VM is better?
by ShinyLeftPad 1mo ago
I heard containers aren't very secure and VM is better?
- MrDrMcCoy 1mo agoDocker containers aren't very secure because the daemon runs as root by default. Rootless container runtimes are plenty secure, especially if the user that runs the container is unprivileged. Easiest thing in the world with Podman.
- ShinyLeftPad 1mo agoWould you run Podman from your own user or another specially created user?
- MrDrMcCoy 1mo agoI would have them run as a user that does not have sudo. The easiest way to do this is by using system-level Podman Quadlets that run as an unprivileged user account. That user will need a real home directory for images and volumes.