"we were talking about having one rouge app"
nobody in this thread was talking about a "rouge-app". we talked about webapps/processes getting hacked in general. we didn't specify how it's getting hacked.
"we were talking about having one rouge app"
nobody in this thread was talking about a "rouge-app". we talked about webapps/processes getting hacked in general. we didn't specify how it's getting hacked.
"SHIPPING CONTAINERS dont help with security"
no. you guys just said it a lot..
---
i repeatetly asked for evidence and you didn't provide me anything.
"if it's so unsecure, why did none of you LINK me reallife-examples of hacked processes breaking out of docker containers?"
https://mastodon.satoshishop.de/@mk/111847966227810935
"you guys are pretty good at talking and pretty shitty at linking to your sources."
https://mastodon.satoshishop.de/@mk/111844129068587581
stop talking, start linking
https://mastodon.satoshishop.de/@mk/111844103725119686
"or just run 16 processes on the host machine"
without containerization?
your answer: yes
---
so you're team one basked (no process isolatin)
great !
I am team one basket with process isolation (containers)..from the start.
YOU seem to switch teams a lot...
"run it in a vm"
https://annihilation.social/objects/72331913-a20c-4303-ab62-12872b91608d
"You understand THAT A VM HOSTS MORE THAN ONE SERVICE."
https://annihilation.social/objects/31ce2e17-11fb-4bb4-b0dd-82e48dde942a
"or just run 16 processes on the host machine"
without containerization?
"You seems to want to prove my point more :mel_laugh:"
how?
the argument tldr..
you: docker too complex
me: complex?
you: everything!
me: install easy
you: MANUAL INSTALL !
me: no adoption. devs support docker ! <3
"You understand THAT A VM HOSTS MORE THAN ONE SERVICE."
and if you don't isolate them, one hacked webapp is going take over EVERYTHING !
customer: please run these webapps
- nextcloud
- peertube 1
- peertube 2
- mastodon
- hedgedoc
- gogs
- excalidraw
- elk_cluster
- searx
- lightning network daemon (testnet)
- lightning network daemon (mainnet)
- bitcoin fullnode
- bitcoin mempool stats
- wordpress
- mailcow emailserver
please run these services for me.
you: we'll run 16 operating systems and you gotta pay me for pushing software updates to every one of those.
customer: too expensive
counter question.
what's got more adoption?
installing shit via docker or bash-scripts?
your customer doesn't want to run 16 VMs, because it's too expensive.
https://mastodon.satoshishop.de/@mk/111843926971242212
https://mastodon.satoshishop.de/@mk/111844044661439465
we already went through this argument. it's a ressource (and management btw) nightmare.
i don't believe you.
is your argument that docker is too complex? -> "In every sense?"
installing software is part of too complex in "every sense", correct?
ok..here's a 10min video that enables noobs to install a bitcoin lightning network daemon that reachable from the internet without the need of:
- a static ip
- a public ip
- a domain name
- a ssl certificate
- portforwarding in the router
- firewall rule in the router
https://mastodon.satoshishop.de/@mk/111819231243916351
docker makes it god damn easy.
in this senacrio you have to, because your customer is forcing you to do it. stop pivotting.
"It has no real benefits"
please answer the question:
"if you've got bad software, would you rather run in inside or outside a container?"
is your argument that docker is too complex?
complex in what sense?
the argument is that docker/containers in general don't have to run within a virtual machine.
"containers provide absolutely no additional security"
then it would be pretty easy for you to proof your statement? i'm waiting.
im running a proxmox server with 2 virtual machines (pfsense and docker).
my docker vm hosts these services:
openldap
nextcloud
peertube 1
peertube 2
mastodon
hedgedoc
gogs
excalidraw
elk_cluster
searx
lightning network daemon (testnet)
lightning network daemon (mainnet)
bitcoin fullnode
bitcoin mempool stats
wordpress
mailcow emailserver
your solution is to..what?
run everything in their own VM? -> ressource nightmare
run everything on one host (without container)? -> security nightmare
bro..you're retarded.
076萌SNS is a social network, courtesy of 076. It runs on GNU social, version 2.0.2-beta0, available under the GNU Affero General Public License.
All 076萌SNS content and data are available under the Creative Commons Attribution 3.0 license.