Securing Services with Rootless Containers for Better Protection
Many developers mistakenly believe Docker containers provide sufficient security, but rootful setups can still lead to full host compromise. I explain how running rootless containers with Podman limits an attacker's impact to an unprivileged user. By leveraging user namespaces and systemd service units, we can deploy services like PostgreSQL and Anubis with significantly reduced risk without needing complex daemon configurations.
There is a common belief among many backend developers stating that Docker containers are a good security layer for their deployed services and applications. However, this is not the case.
- kayson
I'd still rather use docker. I don't mind that the daemon runs as root because there are some things that you need root for anyways! Like binding to privileged ports or setting up networks (use `internal: true` and the daemon will automatically set up iptables rules that limit traffic).
I deploy docker compose files with ansible so everything comes with built in security defaults like rootless, dropped caps, no new privileges, etc. I wish more containers supported running read only (its usually pretty easy to add, just overlooked) and distroless (common for go apps, less so otherwise).
There was a pretty good comment on reddit a while back with a list of hardenings for compose files [1]
1. https://www.reddit.com/r/selfhosted/comments/1pr74r4/comment...
- seemaze
The '--userns=auto' argument is a useful isolation method in both rootless and rootful Podman containers. This allows rootful Podman to orchestrate privileged capabilities while running the container processes in an unprivileged namespace.
See the discussion here:
https://github.com/podman-container-tools/podman/discussions...
- firasd
Interesting... yeah if you think of Docker as an easy way to setup environments that's one thing but if you are intending airtight isolation so processes inside Docker can't "escape" most conventional use cases / discourse haven't really focused on that I think