logoalt Hacker News

imglorplast Wednesday at 12:31 PM1 replyview on HN

> Separation of concerns

Sorta: yes the container is immutable and can be restarted, but when it does, it has the same privs and creds to phone up the same DB again or mount the same filesystem again. I'd argue touching the data is always the problem you're concerned about. If you can get an exec in that container you can own its data.


Replies

neomlast Wednesday at 1:40 PM

Why do you think ISOs never really took off? I feel like they solve so many issues but only ever see folks reach for containers.

show 1 reply