Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
moody5bundle
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
moody5bundle
4y ago
this is the same as: %wheel ALL=(ALL) NOPASSWD: ALL effectively disabling sudo completely.
2.
▲
by
moody5bundle
4y ago
Yup, and based on that mapping table the process inside the container is not allowed to create another namespace and/or fuse-overlayfs. That's why you need to mount /dev/fuse into the container (you might also need cap_s
3.
▲
by
moody5bundle
4y ago
cgroups v1 had some issues: https://nvd.nist.gov/vuln/detail/CVE-2022-0492 and: https://nvd.nist.gov/vuln/detail/CVE-2022-0185
4.
▲
by
moody5bundle
4y ago
Maybe you should include this into your "research": - https://opensource.com/article/19/2/how-does-rootless-podman... - https://github.com/containers/podman/blob/main&
5.
▲
by
moody5bundle
4y ago
Docker is running a daemon with root privileges to start all containers. So if your start a container with "docker run -d ...." you talk to a privileged process. That in turn means, all spawned containers can have root privileges
6.
▲
by
moody5bundle
5y ago
that is exactly what this is intended for :) look at this dockerfile: https://github.com/mody5bundle/capps/blob/main/container/san... and this "config" lines https://github.com
7.
▲
by
moody5bundle
5y ago
depends on your use case. I wanted a way of removing network access for my text editors and starting ephermal firefox instances that are completely independent from each other. Its just an easier way to hack around an application tbh.
8.
▲
by
moody5bundle
5y ago
Flatpak with Dockerfiles and yaml config! :)
9.
▲
by
moody5bundle
5y ago
i think they use bwrap as mentioned in a comment below. my use case is to restrict network access for example. Or running multiple firefox instances in parallel (so they dont have the same parent process / cookies etc.). or restrict me
10.
▲
by
moody5bundle
5y ago
Oh didn't know about bwrap yet! If i understand the wiki page correctly, you still need to get those binaries to your pc. So thats why i went with plain and simple dockerfiles.
11.
▲
Show HN: GUI Applications in Podman on Wayland
(github.com)
97 points
by
moody5bundle
5y ago
|
15 comments
12.
▲
by
moody5bundle
5y ago
if you want to remove network_mode=host you need to run firefox with the --no-xshm flag
13.
▲
by
moody5bundle
5y ago
here you go: https://github.com/mody5bundle/capps please feel free to open issues and pull requests :)
14.
▲
by
moody5bundle
5y ago
I will! cleaning up now and going to publish it later on github. The main idea was a least privilege approach to running simple desktop applications independent from the host OS and being able to control filesystem/network access on a
15.
▲
by
moody5bundle
5y ago
I am actually running a few of my daily applications, such as firefox, vscode, or spotify inside a podman container (rootless makes me feel a little safer). I build a small python script around it, which creates a desktop icon, tags the c
16.
▲
by
moody5bundle
5y ago
that's probably what happened, i reached out to github and hope to get it changed. It just left me at unease. The mighty Linus involved in an organization that redirects to a crypto scam? Can't be!
17.
▲
by
moody5bundle
5y ago
Thank you, i just did!
18.
▲
Ask HN: Is Linus Torvalds GitHub page a scam?
11 points
by
moody5bundle
5y ago
|
4 comments