Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The user using this has to be in that group, the programs being run do not.

For a single-user machine, it may be okay. But I don't trust Docker's security very much.



any particular reasons you don't trust Docker security?


The daemon has had many security issues. They also only recently grew support for ACLs (which are only available as plugins), so any user that can write to the Docker socket is essentially equivalent to root.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: