2 ms·
>It might be a stupid question but I wonder what's considered a leaky abstraction in this case. I consider poking a hole a leaky abstraction because you are ex
by Xdes 13y ago
>It might be a stupid question but I wonder what's considered a leaky abstraction in this case.
I consider poking a hole a leaky abstraction because you are exposing the internals of your stack. The consumer should not know or care that you are using docker containers to serve the application. From a security perspective directly exposing a container may lead to potential exploits of docker itself.
- cpuguy83 13y agoExposing a container would not to exposing potential exploits of Docker. Docker is not running in the container (and doesn't know anything about Docker). Exposing a container is a hell of a lot safer than exposing a service on the host OS. Also not sure I follow you how a consumer would know you are using docker or not.