pucker4676
@pucker4676@lemmy.ml
- Comment on Portainer 3.0 is coming, and here's what it means for you — Portainer 3 weeks ago:
Well, I learned something new. I didn’t know Portainer supported Podman. I guess it shouldn’t be that surprising, Cockpit does as well.
Any time you’re giving software access to your system you’re increasing attack surface. Even with podman, if you’re running containers properly, the containers have separate users, so your management system is most likely going to need root access. Or at the very least a common group which makes the segregation a moot point.
This topic is always going to be highly personal. Some care, some do not. If you’re only running a media server, then who cares if it’s all lost, but if you’re also hosting all your photos, sensitive documents, etc… It becomes a huge risk for everything to mingle with root access. I can’t imagine anyone would want a third party hanging out behind their firewall regardless.
- Comment on Portainer 3.0 is coming, and here's what it means for you — Portainer 3 weeks ago:
You can customize the hell out of your terminal emulator. As I said in the other comment, you do you. It’s a security risk, but it’s not my box.
- Comment on Portainer 3.0 is coming, and here's what it means for you — Portainer 3 weeks ago:
I understand a GUI can be nice to look at, but it can also be a security risk. More permissions, more attack surface. It’s largely an unnecessary addition. But you do you. It’s not my box. I’m trying to migrate from docker to rootless podman. It’s been on my to-do list for quite awhile. There’s only so much segregating you can do with a rootful daemon.
- Comment on Portainer 3.0 is coming, and here's what it means for you — Portainer 3 weeks ago:
There’s no time like the present to familiarize yourself with the CLI commands. Docker’s pretty basic. Less is more.