haliphax,
@haliphax@hachyderm.io avatar

Seen some grey-beards dogging on using containers to deliver applications lately, and I'm of two minds about it.

I understand the kernel of the argument, and I don't disagree with it.

On the other hand, I am currently working on a community server composed of many services:

  • SSH server
  • API server
  • nginx server
  • postgres server
  • redis server
  • proxy/load balancer

Does this need containers? No. Would it be less confusing/error prone without using them? Also no. Fuck no.

haliphax,
@haliphax@hachyderm.io avatar

I have taken measures where I can to try and eschew problems by pinning any of the dependencies I install at the OS level when building my own containers, but in terms of the off-the-shelf variety (e.g. postgres, nginx, redis, base OS containers), I am nowhere near as qualified as the image maintainers themselves to keep track of this shit.

At some point, you have to trust somebody else. Where that point lies will vary based on your project's level of concern. 🤷

haliphax,
@haliphax@hachyderm.io avatar

All this being said, you absolutely should be vetting your containers with at least an iota of due diligence. If they're curling from a rando's GitHub repo and piping a script into sudo sh, then maybe look elsewhere.

I just don't think that I need to care as much about the officially-blessed redis container image from DockerHub, etc. ... attackers could pwn me from a local redis binary install just as easily (or easier) given my level of expertise with this stuff (which is ... not great).

urda,
@urda@urda.social avatar

@haliphax proper groups DO verify their Software Bill of Materials (SBOM). We have entire teams at Blue dedicated to it.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • DreamBathrooms
  • magazineikmin
  • thenastyranch
  • modclub
  • everett
  • rosin
  • Youngstown
  • slotface
  • ethstaker
  • mdbf
  • kavyap
  • osvaldo12
  • InstantRegret
  • Durango
  • megavids
  • ngwrru68w68
  • tester
  • khanakhh
  • love
  • tacticalgear
  • cubers
  • GTA5RPClips
  • Leos
  • normalnudes
  • provamag3
  • cisconetworking
  • anitta
  • JUstTest
  • All magazines