Comment on Alternative to ClamAV?

<- View Parent
jlh@lemmy.jlh.name ⁨9⁩ ⁨months⁩ ago

I respectfully disagree. Containers are 100% the right choice in this situation. They provide the defense-in-depth and access controls that combat the threats that OP is targeting by using ClamAV.

The goal isn’t securing a single database through a single attack vector. And it’s not like ClamAV would help you with that, either. The goal is preventing attackers from using your infra’s broad attack surface to get inside, and then persisting and pivoting to get to that database.

It’s just not true that you can get the same level of security by running everything bare-metal, especially as a one-man, self-hosted operation.

source
Sort:hotnewtop