logoalt Hacker News

Lutgeryesterday at 5:00 PM4 repliesview on HN

Everything runs in the container and cannot escape it. Its like a sandbox.

You have to make sure you're not putting any secrets in the container environment.


Replies

roozbeh18yesterday at 5:26 PM

You are just reducing the blast radius with use of podman; you will likely need secrets for your app to work, which will be exposed regardless of the podman approach.

show 2 replies
eybergyesterday at 10:19 PM

No it is not.

mlnjyesterday at 5:11 PM

>You have to make sure you're not putting any secrets in the container environment.

How does this work exactly? containers still need env vars and access to databases and cloud environments. Without these the container is just useless isolated pod.

show 3 replies
moffkalastyesterday at 5:05 PM

All right then, keep your secrets.