3 ms·
Neat. Just be cautious as docker containers aren't yet secure. https://docs.docker.com/articles/security/ https://docs.docker.com/articles/security/
by syncerr 11y ago
Neat. Just be cautious as docker containers aren't yet secure.
https://docs.docker.com/articles/security/ https://docs.docker.com/articles/security/
- rmgraham 11y agoThanks for taking a look, and looking close enough to see that it uses Docker :-) Was there some specific aspect or attack vector that came to mind? Or did you mean it more as a blanket warning?
- syncerr 11y agoGenerally. And only because I see other companies doing this sort of thing. I'd like docker to be a solution here, but we're not quite there.
- anonova 11y ago> Docker containers are, by default, quite secure; especially if you take care of running your processes inside the containers as non-privileged users (i.e., non-root). I'm not quite seeing the sense of insecurity here, especially from the conclusion. Like any piece of software, it's up the user to not use "dangerous" configurations.
- azernik 11y agoExcept that the default is for processes inside containers to run as root. So, "by default, quite secure; except this one default that exposes you to some very nasty attacks unless you override it".
- marcosdumay 11y agoLinux containers are at most a privilege escalation away from breaking. Also, isn't Docker people the ones talking about unikernels? Where everything run not only with superuser powers, but at kernel level?
- rmgraham 11y agoThough in a Unikernel, the kernel only implements what is needed to run the service. So a database, for example, would be lacking functionality like a shell to escape to.. or even a TTY to run that shell on.. or an implementation of connect() to even initiate outbound TCP connections, in the extreme case.