3 ms·
I would really prefer when Docker, Inc would spend their time and effort in securing their core product rather than extending it all the time by adding more and
by geku 12y ago
I would really prefer when Docker, Inc would spend their time and effort in securing their core product rather than extending it all the time by adding more and more features like Machine, Swarm, etc.
- kofalt 12y agoAccording to Red Hat, the current best way to secure your Docker usage is to `127.0.0.1 index.docker.io` and use an alternate transport. The core "translate flags into running container options" works fine IMO, it's the centralized transport causing the issue. Which isn't the end of the world, as distributing tarballs is not exactly a demanding task. As an example / plug, I helped write a (prototype) tool that lets you import a docker image from the registry, then transport / version it separately: https://github.com/polydawn/hroot https://github.com/polydawn/hroot Thus, integrating via `docker load` + `docker export` is possible & reasonable. Linked from the article: https://securityblog.redhat.com/2014/12/18/before-you-initiate-a-docker-pull https://securityblog.redhat.com/2014/12/18/before-you-initia...