8 ms·
Docker Desktop: Your Desktop over ssh inside of a Docker container
- VaucGiaps 13y agoLinux != Debian
- icebraining 13y agoThe script is actually Ubuntu specific, not Debian (it uses Upstart).
- jol 13y agoI can see usig this to get perfectly replicable, easy to upgrade/rollback and movable works environment - for both local and remote use. I.e., use locally on powerfull machine or rdp to closest powerful machine you can access from slow device. Or have several workspaces similar to virtual desktops for multiple projects...
- rogaha 13y agoExactly. You can easily do that with Docker Desktop :)
- beachstartup 13y ago> root@host:~# curl http://get.docker.io http://get.docker.io | sh No no no. Do NOT do this. Kids these days...
- tlrobinson 13y agoHonest question: do you audit every line of code you ever download and execute? Edit: Ironically Docker itself has the potential to help solve the problem of running untrusted open source code. I think every open source project should include either a Dockerfile or Vagrantfile to help users get up and running quickly, and safely run untrusted projects.
- jol 13y agoI don't, but for install script one can look at least from where the stuff will come. if the download link was using ssl...
- tlrobinson 13y agoI agree, they should use SSL (and don't use a URL shortener, which they don't, but I've seen before). Ideally it would download a file from Github too, that way you can be sure it's coming straight from the publicly visible open source repo, and you can audit if you want. But I think the general outrage over this technique is overblown.
- jlgreco 13y agoWhy don't we just add "click to execute" to browsers while we are at it... /s
- tlrobinson 13y agoBecause people who use command lines / open source software generally have better judgement about this sort of thing than the average user? You either have to trust Docker (a fairly well known project built by reputable people) isn't going to root your machine, or download the source yourself and audit it. This is no worse than suggesting you "git clone whatever; cd whatever; make" (aside from the lack of SSL)
- jlgreco 13y ago> You either have to trust Docker ...and everybody else on my network, with that method. Doing that I don't even get the chance to think "Hey wait a second, why was this only 50 bytes of shell script...". The reason that you see outrage for this "method" is because it is born of laziness and far too reminiscent of more disturbing times in computer security.
- tlrobinson 13y ago
- beaumartinez 13y agoYou can curl the URL and see what it is you'll be executing. You don't get that with an obscure binary you download from the web. But the URL should be HTTPS.
- rogaha 13y agoYou can also install using this procedure: http://docs.docker.io/en/latest/installation/binaries/ http://docs.docker.io/en/latest/installation/binaries/
- malandrew 13y agoIs there any tool to automate the introspection of curl pipes to warn of potentially malicious code that needs to be given further attention? The usability of the curl pipe approach is here to stay, so the least we can do is help people be safe with it. Anyone have other ideas for making curl pipes safer?
- RodgerTheGreat 13y agoWell, detecting potentially malicious shell scripts is merely a matter of solving the halting problem... Food for thought: http://www.cs.dartmouth.edu/~sergey/langsec/ http://www.cs.dartmouth.edu/~sergey/langsec/
- malandrew 13y agoWould there be any benefit in creating a VM on the fly, running the shell script in the VM and there reporting back on what was modified by the shell script. If all goes well, I reckon you can then safely run the script on the host machine.
- RodgerTheGreat 13y agoEven if you can be bothered to semi-manually audit the changes a script applies to the VM and can afford the time and space overheads of such a "guess-and-check" approach, a malicious server could send you a different script the second time you requested it, or the script could in turn pull down other payloads differently the second time it executed. If you try to extract a diff of the changes applied to the VM and then reapply it to your host machine to ensure the behavior is the same, why not simply have an installer system which behaves in a more restricted way to begin with? The root of the problem is that shell scripts fetched from remote servers are far too flexible to be 'safe'.
- vidarh 13y ago... except when someone writes a script that guesses (or reliably detects, depending on container technology) whether it's running in a VM/container and acts differently then. Or if it only acts maliciously say, one out of five times ("old school" viruses would often do that - destroy your floppies sometimes, but most of the time just spread).
- Groxx 13y agoOf course, because binaries are incapable of doing the same thing as `curl x | sh`...
- burke 13y agoOne alternative would be a graphical installer that asks for your root password. It would very likely also be served over unencrypted HTTP. This happens all the time, and HN never calls anyone out on it. How is this different, other than a graphical installer being completely unauditable, whereas curl|sh is quite trivially auditable? Both run code as root.
- txutxu 13y agoI think there is more danger in html5 dinamyc fonts, or more evil in a dns request, than an opensource project installer. Of course, don't do this on your most beloved production machine, if you can package it properly, test it, etc But rendering a font gives execution with your user, so don't be so afraid of a installer "you can read" and has an interesting purpose.
- antocv 13y agoThis also sucks because the scripts always assume some variant of Ubuntu or Debian. Um, no, thank you, damn hipsters.
- mateuszf 13y agoOn Arch Linux installation is as simple as chosen_aur_wrapper -S lxc-docker-git
- drivebyacct2 13y agoOn what planet is an Ubuntu user a "hipster"?
- throwaway2048 13y agodrivebyacct2 you are hellbanned, time for drivebyacct3 i guess
- shykes 13y agoThe website offers install instructions for several OSes: http://docs.docker.io/en/latest/installation/ http://docs.docker.io/en/latest/installation/
- slashdotdotorg 13y agoExactly _what_ is your qualification for debian being lumped in with hipsters? Some of us have used it as the most rock solid STABLE linux distro for servers and desktops for quite a long time.
- antocv 13y agoI apologize to Debian users. Respect.
- peatmoss 13y agoHe's an avid Yggdrasil user. As an aside, I miss some of the raw diversity that was present in the old Linux distros. Slackware was my drug of choice due to its steadfastly BSD flavor. I guess Slackware is still around, but have no idea what its status is and whether Patrick ever moved it over to system v-ish convention in order to be more like other Linux distros. I guess that distinction is even a bit anachronistic given all the fancy changes to the way init is done nowadays.
- anonymoushn 13y agoThis is how rvm's authors want you to install rvm :)
- kawsper 13y agorvm uses https, which is far better than plain http.
- rogaha 13y agoI have updated the blog post with a more secure way of installing docker.
- j_s 13y agoI got excited when I saw the Windows installation instructions link, but that is just how to setup Vagrant with VirtualBox to host a Linux machine. Is there any open-source equivalent to things like Citrix's XenApp, VMWare's ThinApp, Microsoft's App-V, or independent tools like Sandboxie? http://alternativeto.net/software/sandboxie/ http://alternativeto.net/software/sandboxie/
- rufugee 13y agoWe've been experimenting with Ulteo (http://ulteo.com/home/ http://ulteo.com/home/) as a possible alternative to XenApp.
- rogaha 13y agoSorry, but for now it's the only way to install it on Windows. Thanks for asking j_s.
- mmgutz 13y agoBut why Vagrant? It's an unnecessary dependency that requires installation of more stuff I don't use. Why not distribute a pre-built VBox image and torrent it?
- jahewson 13y agoThinApp, App-V, etc. are pretty much equivalent to a chroot jail on unix.
- gcb0 13y agoSo, if I understood that correctly, it's just a virtual box image of ubuntu or debian that you run headlessly in a linux container (via docker) and then run a Xserver on your actual machine OS and connect to it via SSH with Xforward? how is this any better than simply running virtualbox on your OS to begin with?
- rogaha 13y agoExactly. It's better because you can build that image anywhere where there is docker installed and it can be easily moved/upgraded and ready to run. But if you think only locally, then there is no much difference, despite that docker lighter and faster.
- yebyen 13y agoFurther, the VirtualBox instructions are only for Windows users, to get Linux installed (which is a requirement of Docker). You don't need VirtualBox at all. But if you don't have Linux, you can try this with VBox (it's a virtualization tech that nests safely inside of vbox... unlike say, virtualbox inside of virtualbox.)
- gcb0 13y agoif i already have linux installed i can carry fat binaries and a kernel for chroot'ing an environment. all in a tar file... I think this is just new way kids does common things of yesterday. or maybe linux containers kicks chroot a in performance?
- yebyen 13y agoto me it's not about performance... it's about rigorous isolation. LXC is like FreeBSD jails, though there are things you can do with the cgroup namespace stuff now that are impossible using jails... eg. disk io accounting. in a jail, one user who attempts to monopolize disk io will succeed. in a cgroup, he can be restricted to exactly 10% of available i/o bandwidth, so you can guarantee that he doesn't starve the other containers. there are also easy and documented ways to break out of a chroot if you are able to obtain root in the chroot. those holes are plugged by lxc and docker. Most notably, access to devices can be restricted. I don't know what you mean by "carry fat binaries and a kernel for chrooting an environment" -- you don't need a separate kernel for chroot, any more than you need a separate kernel for docker. There's no advantage to static linked binaries (fat binaries?) when you can put the storage of your containers in a zpool or btrfs with deduplification. Same as your chroots. Try out docker. Read about cgroups. I first gave LXC a try a few years ago and I was really sad about the extent of support for creating guests and keeping them properly isolated. It was really not friendly at all. You basically had to commit to using kernel patches that made your system pretty unusable as a desktop. (Was that xen dom0 or lxc?) Everyone was saying, "Ohh, LXC is no better than a chroot." It's insecure, easy to break yourself out. Not so much anymore, with the current state of Docker you don't even have to know all the advances in cgroup and namespaces. It's worth a look. Really, go check it out.
- ivan_ah 13y agoThis could be made VERY interesting if you also add an NX server in the mix. I find basic X11 connections via ssh to be rather laggy and unpleasant to use when the internet connection is not top. The idea behind NX is to "fake" an X client on the server side and fake a NX server on the client side. This reduces the number of roundtrips required for each action. The improved responsiveness is dramatic -- even on a low speed and high-latency link, using the remote desktop feels like a local machine... http://en.wikipedia.org/wiki/NX_technology Unfortunately, the two open source projects which aimed to reproduce the NX functionality seem to have been abandoned. http://freenx.berlios.de/ http://code.google.com/p/neatx/source/list Is anyone using NX these days? Perhaps, people stopped developing these because they work well already?
- rogaha 13y agoI didn't know NX! Thanks for suggesting it Ivan! I will try it !
- cpach 13y agoX2Go[1] is under active development and to my understanding it's based on NX libraries. It might be a good alternative. I have only tried it briefly and not over WAN, but it worked quite good over WLAN at least. [1]: http://wiki.x2go.org/doku.php/start http://wiki.x2go.org/doku.php/start
- morsch 13y agoWe're using NX/x2go for working from home or, sometimes but fortunately not too often, less likely remote places such as weekend holiday places. It does work well. I wouldn't go as far as saying it feels like a local machine, and it's not as responsive as regular X over a fast LAN, either. But it's very usable.
- sciurus 13y agoIMHO here's an even cooler hack- Gtk+, the widget toolkit used to develop GNOME and many free software applications, supports rendering applications via HTML5. One of the developers has demonstrated using it to run desktop applications on OpenShift, Red Hat's PaaS, that you then access via your web browser. http://blogs.gnome.org/alexl/2013/03/19/broadway-on-openshift/ http://blogs.gnome.org/alexl/2013/03/19/broadway-on-openshif... http://blogs.gnome.org/alexl/2013/04/03/more-gtk-in-the-cloud/ http://blogs.gnome.org/alexl/2013/04/03/more-gtk-in-the-clou...
- StavrosK 13y agoBut... but... how?
- willvarfar 13y agoHere's a recipe for using vnc to get pixels out of a docker: http://stackoverflow.com/questions/16296753/can-you-run-gui-apps-in-a-docker http://stackoverflow.com/questions/16296753/can-you-run-gui-...
- DannoHung 13y agoIf you're sort of confused as to what advantage there is to this way of doing things over just running a VM in VirtualBox or using Vagrant, you probably aren't yet aware of what the Docker project is doing. It's creating the VirtualBox of Linux Containers. Docker image files are extremely light weight when compared to VirtualBox images and use Union File systems to allow for complete isolation rather than using VM volumes. An example scenario for when you'd want something like this is if you want to load an experimental library for a specific application that some part of your system depends on the stability of. Fire up a docker image for just that application with the experimental library replacing the stable library and just the applications inside the docker image will see it. No need to even play around with library versions or links. And since the Docker images are so light weight and incur extremely little performance penalty (I think it is limited to just the cost of using the Union FS over your normal FS), you can do this for dozens of scenarios at once.
- rogaha 13y agoGreat explanation! Thanks DannoHung
- zobzu 13y agoI'm confused with the advantage over "pure" LXC and a couple of scripts for the mounts, what does it provides for this kind of usage? Or is it not using LXC and basically implements its own interface to the Linux namespaces? (that'd be actually cool... :P)
- shykes 13y agoDocker does use lxc under the hood. They serve very different purposes. lxc is a tool for sysadmins to deploy and configure virtual servers on their machines. docker is a tool for developers to package their application into a deployable object without worrying about how the sysadmin will deploy it, and for sysadmins to deploy applications without worrying about how they were packaged. When you tinker long enough with lxc, eventually you start building something like docker on top of it, because it just makes sense. Now instead of reinventing the wheel you can just use docker.
- 13y ago