Making containers safer
Making containers safer
Posted Aug 22, 2019 8:41 UTC (Thu) by corsac (subscriber, #49696)In reply to: Making containers safer by cyphar
Parent article: Making containers safer
Fair points, but I think you missed the “et al” part. And yes I'm aware that capabilities are not perfect (far from it) and a lot of them are equivalent to SYS_ADMIN / full root. But dropping the relevant caps still seem more reasonable to me than exposing the kernel. There's still a lot of stuff not namespace-aware and thus a large attack surface which is reachable when you're uid=0 in a user namespace.
