3 ms·
Well the code to every part of this is open source so you can check and improve. The hosting part is on 10 digital ocean boxes all with one container on it so t
by Pellepelle3 11y ago
Well the code to every part of this is open source so you can check and improve. The hosting part is on 10 digital ocean boxes all with one container on it so the build process is more isolated and anything goes wrong we kill and spawn a fresh box.
- Pellepelle3 11y agoWe also encourage people to host them selves. To have it completely there own.
- jzelinskie 11y agoDocker executes builds as root which provides a build the opportunity to escape the container and become root on the host machine. In containerfactory.io's current hosted setup, there are no guarantees that the machine an image is being built on hasn't already been compromised by a previous build. Quay.io has traditionally worked around this problem by patching user namespaces into docker, but they come with their own set of incompatibilities. As a result, we have found the best solution is to never trust the build machines given the risk of credentials being taken or builds being manipulated. Hosting your own copy completely avoids this issue, if you trust the people you work with ;)
- toomuchtodo 11y ago> Hosting your own copy completely avoids this issue, if you trust the people you work with ;) We build containers from ephemeral t1.micros that only survive long enough to build the single container. I think that's secure enough for most orgs needs.