logoalt Hacker News

kaysonyesterday at 8:55 PM4 repliesview on HN

I'd still rather use docker. I don't mind that the daemon runs as root because there are some things that you need root for anyways! Like binding to privileged ports or setting up networks (use `internal: true` and the daemon will automatically set up iptables rules that limit traffic).

I deploy docker compose files with ansible so everything comes with built in security defaults like rootless, dropped caps, no new privileges, etc. I wish more containers supported running read only (its usually pretty easy to add, just overlooked) and distroless (common for go apps, less so otherwise).

There was a pretty good comment on reddit a while back with a list of hardenings for compose files [1]

1. https://www.reddit.com/r/selfhosted/comments/1pr74r4/comment...


Replies

drnick1yesterday at 10:42 PM

Rootless is definitely the way to go. You can forward ports manually on the host if you really need to use privileged ports. I generally expose my containers through a reverse proxy, running bare metal on the host, and that completely bypasses the privileged port issue.

nine_ktoday at 1:12 AM

Give your binary CAP_NET_BIND_SERVICE capability, and run it as a regular user. Almost no daemons need to run as root.

LelouBiltoday at 12:11 AM

I get the savings of Distroless, but when you have an issue it's a pain to debug.

show 1 reply
latchkeyyesterday at 10:00 PM

just curious why you'd bind to a priv port inside of a container.

show 1 reply