4 ms·
Assuming you are arguing in favour of VMs, the benefits of Docker stand, and you can perfectly run Docker containers within a VMs. The feature sets/usage sweet
by thu 12y ago
Assuming you are arguing in favour of VMs, the benefits of Docker stand, and you can perfectly run Docker containers within a VMs.
The feature sets/usage sweet points of OS-level package managers, language-specific package managers, VMs, containers, distinct/same hosts, ... are both overlapping and different enough that you need judgement to choose which one you want, but they are certainly not exclusive.
If your use case means you prefer VMs over containers and you don't need to combine them, fine, but every situation is different.
- meatmanek 12y agoThere are valid concerns. Someone with access to the docker control socket effectively has root on your machine: e.g. `docker run -v /etc:/external_etc ubuntu visudo -f /external_etc/sudoers`. Don't let untrusted users (or scripts) run docker.
- icebraining 12y agoWhich is exactly what the Docker docs say: "First of all, only trusted users should be allowed to control your Docker daemon." http://docs.docker.io/articles/security/#docker-daemon-attack-surface http://docs.docker.io/articles/security/#docker-daemon-attac...
- msane 12y agoThis is a good point but applies to other tech that seeks some of the same ends. And if an attack is penetrated that deep then you would be screwed anyway. What's nice from a security perspective is Docker actually lowers the attack surface and shrinks the access that any potential outside attack can have.