• 1 Post
  • 24 Comments
Joined 2 years ago
cake
Cake day: June 28th, 2023

help-circle
  • Indeed. Sure, they have these features, but only if used correctly while introducing vast more complexity (especially when being executed in a k8s environment,but also executed in plain docker). But, you know what also has security when used correctly? Plain linux.

    What about 90% of all images on docker hub executing their main payload as root? What about many images bundling unnecessary software like an init system? What about the fact that even if you rm something in a dockerfile, it is still present, if you execute the rm in a different RUN command? What about every user in the docker group being implicit root on the host since they simply can mount the host’s / inside their container? What about the reusing of layers between images like it is even intended?

    Doesnt sound like a security tool, does it? Sure, it feels a bit like one, but it was never intended to be one, but a dependency and environment bundling tool which happens to use certain linux APIs which can be used for security. But it wraps lots of abstraction around it.

    If you want to use these features for security, access them manually. But, OP said they are kind of a noob. Telling them to just use containers is dangerous and leads to false assumptions.

    Source: i work as a cloud/container/devops/k8s expert for over 5 years.







  • ttk@feddit.detoAsklemmy@lemmy.mlSelf-care for Men?
    link
    fedilink
    English
    arrow-up
    11
    ·
    1 year ago

    Going to the barber. Not only do i look nice afterwards, but this hour of simply doing nothing while nice people are around, good music and maybe a glass of whisky or a coffee is quite good.

    Visiting a thermal bath/sauna. Afterwards i am pretty relaxed and tired. Sure, you must get used to the “no clothing allowed” policy, but you can use a towel, and everyone around is also naked and as fat and ugly as yourself.

    Driving around on my ebike on a summer evening with good music on my airpods, enjoying the weather and spectating other people enjoying the evening outside.






  • When i was at my first job in a factory as a trainee, they decided to remodel a manufacturing line and had to move some 40t hydraulic presses. They hired a crane, and the crane guy did the proper mounting of the presses. A 20cm steel beam through the mounting holes of the press, attached to the hook of the crane with these nylon carrying ropes. All fine.

    As he lift the press through a hole in the roof, the steel beam just fucking breaks into two pieces. The whole 40t press falls to the ground from a height of 3 meters, leaving a crater of 50cm in depth in the concrete. The broken off piece of the steel beam slams into the driver cabin of the crane, which luckily was reinforced with a steel cage behind the window. This cage saved the crane operator’s life.

    We were on a smoke break and watched everything. Fucking crazy.

    Never step under heavy load hanging from a crane. Never ever.