2 ms·
> I always make my user part of the docker group I don't, and I migrated to Podman because Docker is poorly designed and full of footguns. For example, it it w
by drnick1 1mo ago
> I always make my user part of the docker group
I don't, and I migrated to Podman because Docker is poorly designed and full of footguns. For example, it it will silently overwrite iptables rules and punch holes in your firewall.
- PuercoPop 1mo agoIndeed. Podman works great. And kube play unifies container orchestration by using k8s manifests for local orchestration instead of a separate DSL like docker compose.
- jadar 1mo agoThis. It’s easy to let happen too. If you’re on a machine that’s not behind NAT then it’s really easy to pwn yourself.
- dotancohen 1mo agoI'm sorry, what? As an avid Docker user, where should I begin reading about these issues?
- 8organicbits 1mo agoOfficial docs cover those: https://docs.docker.com/engine/network/firewall-iptables/ https://docs.docker.com/engine/network/firewall-iptables/ https://docs.docker.com/engine/install/linux-postinstall/ https://docs.docker.com/engine/install/linux-postinstall/
- dotancohen 1mo agoAre there other things to be wary of, though? It's easy to find information about things one already knows about.