Comment on Dedicated service user or not ?
tty5@lemmy.world 3 weeks ago
It’s always effort vs risk.
Since it’s a do once and forget kind of thing I’d rate effort rather low.
As for risk in the worst case scenario a single service being compromised means all of them are with the attacker getting access to everything those services can access, including all the credentials. Will you make an effort to be on top of all the updates for all services?
At home all containers for any service get a separate user. At work every container does.