Comment on Docker security

<- View Parent
GreenKnight23@lemmy.world ⁨6⁩ ⁨days⁩ ago

What if you rent a bare metal server in a data center?

any msp will work with your security requirements for a cost. if you can’t afford it, then you shouldn’t be using a msp.

Or rent a VPS from a basic provider that expects you to do your own firewalling?

find a better msp. if a vendor you’re paying tells you to fuck off with your requirements for a secure system, they are telling you that you don’t matter to them and their only goal is to take your money.

Or run your home lab docker host on the same vlan as other less trusted hosts?

don’t? IDK what to tell you if you understand what a vlan is and still refuse to set one up properly to segment your network securely.

It would be nice if there was a reliable way to run a firewall on the same host that’s running docker.

don’t confuse reliable with convenient. iptables and firewalld are not reliable, but they are certainly convenient.

You may say these are obscure use cases and that they are Wrong and Bad. Maybe you’re right, but personally I think it’s an unfortunate gap in expected functionality, if for no other reason than defense-in-depth.

poor network architecture is no excuse. do it the proper way or you’re going to get your shit exposed one day.

source
Sort:hotnewtop