7 ms·
Running GUI apps with Docker
- jestinjoy1 12y agoNoob here. What are the possible usecases?
- zwischenzug 12y agoHere's one: http://zwischenzugs.wordpress.com/2014/05/09/docker-shutit-and-the-perfect-2048-game/ http://zwischenzugs.wordpress.com/2014/05/09/docker-shutit-a...
- yuvadam 12y agoSkype, for example, can be run inside a container [1], allowing you to use it while hiding the rest of your system from the obfuscated and traffic-encrypted binary which no one knows what it does to your system. It uses X11 forwarding for the GUI, and PulseAudio for the sound. [1] - https://registry.hub.docker.com/u/tomparys/skype/ https://registry.hub.docker.com/u/tomparys/skype/
- vertex-four 12y agoI'll note that X11 has practically no security and that windows can read contents from other windows, if you happen to be worried about that attack. Essentially, anything that is displayed can be read by anything. You'd need some form of "X11 firewall" to be secure.
- masklinn 12y agoUntrusted SSH X-forwarding (via -X) is a start.
- crdoconnor 12y agoAlso Skype has been caught reading the UNIX passwd file and your firefox profile: http://linux.slashdot.org/story/07/08/26/1312256/skype-linux-reads-password-and-firefox-profile http://linux.slashdot.org/story/07/08/26/1312256/skype-linux... The thing that made me finally uninstall it (from everything) is when my phone OS (MIUI) informed me that Skype wanted to suddenly take a photo of me even though I hadn't touched the app for days.
- reirob 12y agoThis Skype use case really interests me a lot, as I have to use it professionally and do not trust this application at all and would like to limit it to a bare minimum: microphone, webcam, screen and one single folder for file exchange. I never tried Docker, but I wonder, if this requirements can be achieved with SeLinux or AppArmor as they are supported by many distributions and are around longer than Docker? Would be great to be able to tighten the corset around any non open-source application, to make sure it is not siphoning data.
- varikin 12y agoAutomated testing of native clients could leverage this.
- mateuszf 12y agoJust guessing - internet explorer under wine.
- zwischenzug 12y agoNice... previously I'd just installed vnc.
- Lai0chee 12y agohumm, the sudo makes me shudder.
- piqufoh 12y agoWhy? It's being run inside the docker container, it should be ok.
- Lai0chee 12y agoDocker "isolation" is not as strong as most hipsters think. :-)
- wastedhours 12y agoInteresting, any links which expand on the issues?
- tekacs 12y agoI use ssh -X [1] since it runs the application as an untrusted client, not able to interact with or manipulate or sniff from other windows. ssh -Y is the trusted equivalent. Might I assume that the approach in the article gives processes in the container full access to one's X11 session and contents? [1]: SSH X11 forwarding
- deleted 12y ago[deleted]
- foobarqux 12y agoAre there still problems with apps that require the initialization system. I never was able to get things like dbus working in Docker.
- cliftonk 12y agoIf it's helpful to anyone else, I used X virtual frame buffer with VNC to do something similar earlier this year https://github.com/clifton/docker-ib-gateway https://github.com/clifton/docker-ib-gateway
- vivab0rg 12y agoFYI, Fábio Rehm is also the author of the great LXC provider for Vagrant[1], which I sucessfully use for fun and profit almost every working day. PS: I you like Fábio's work, consider tipping him[2] (I already did, with bitcoins! :) [1]: https://github.com/fgrehm/vagrant-lxc https://github.com/fgrehm/vagrant-lxc [2]: https://gratipay.com/fgrehm/ https://gratipay.com/fgrehm/
- zokier 12y agoDoes OpenGL work with this?
- rubyn00bie 12y agoWhile I think this is cool, could someone explain to me why I'd bother using a docker setup over let's say a... traditional VM? And I don't need justification for using containers on a server, that makes sense... on a desktop though something just seems off. Seems like there's little to gain and a lot to configure/worry about with the Docker setup. Happy to be learned somethin' ... just would like to know what that somethin' is.
- yurymik 12y agoThere are a couple reasons I can think of: * You can run different versions of program side-by-side: FF 32 in one window, and FF 31 in another to test compatibility and regression. * You can install programs without polluting your base system. I don't want to have Java installed, but sometimes I just need to run an applet. All of that can be achieved with traditional VM, but with the performance penalty. As Docker runs on top of the native kernel, speed should be comparable to the application running directly on host.
- outworlder 12y agoMy guesses are speed - not that relevant if you are interacting with an app that is waiting for user input - and memory usage. In a traditional VM, you have to reserve memory that is used by the guest OS and the apps you want to run, and is unavailable as soon as the VM comes up. Docker is incredibly lightweight in comparison. Also, you can move your development environment around, same way you would move a VM disk around. That requires less resources, again, as there is no OS install.
- nullsocket 12y agoFirejail anyone? http://l3net.wordpress.com/projects/firejail/ http://l3net.wordpress.com/projects/firejail/
- Aissen 12y agoShare your X11 socket/cookie, and now everything you input (keyboard/mouse,etc.) is readable by a so called "contained" application; this is not a secure solution, but more of a comfort solution, and it should be used as such. On a side note, I've been doing this with chroot/debootstrap for years, but lxc/docker provide a nice "engineered" solution.