LibreTechni.ca
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
cm0002 to Programmer Humor@programming.devEnglish · 4 hours ago

Life finds a way

lemmy.ml

message-square
15
fedilink
  • cross-posted to:
  • programmerhumor@lemmy.ml
130

Life finds a way

lemmy.ml

cm0002 to Programmer Humor@programming.devEnglish · 4 hours ago
message-square
15
fedilink
  • cross-posted to:
  • programmerhumor@lemmy.ml
alert-triangle
You must log in or register to comment.
  • JRaccoon@discuss.tchncs.de
    link
    fedilink
    arrow-up
    2
    ·
    4 minutes ago

    Never ever add any users to the docker group. Rootless mode is cool tho (albeit with some caveats)

  • diabetic_porcupine@lemmy.world
    link
    fedilink
    arrow-up
    3
    ·
    29 minutes ago

    Is that normal config?

  • marlowe221@lemmy.world
    link
    fedilink
    English
    arrow-up
    20
    ·
    2 hours ago

    Slowly reaches for shotgun…

  • uuj8za@piefed.social
    link
    fedilink
    English
    arrow-up
    35
    ·
    edit-2
    3 hours ago

    I mean, there’s a big ol’ warning in the docs: https://docs.docker.com/engine/install/linux-postinstall/

    The docker group grants root-level privileges to the user

    But, I guess Docker doesn’t really tell you not to do this… and I feel like a lot of mac users are not used to adding sudo at the front of docker commands so… idk.

    • Sir. Haxalot@nord.pub
      link
      fedilink
      English
      arrow-up
      11
      ·
      1 hour ago

      … and the Nextcloud developers think it’s completely reasonable to build a plugin system where you give this access to a web facing PHP application.

    • ChromaticMan@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      9 minutes ago

      Sadly, nobody reads docs anymore. Now that I’m thinking, people never read the docs.

    • SpaceNoodle@lemmy.world
      link
      fedilink
      arrow-up
      26
      ·
      3 hours ago

      Sounds like Docker is just inherently unsecure.

      • hperrin@lemmy.ca
        link
        fedilink
        English
        arrow-up
        9
        ·
        3 hours ago

        In the same way that sudo is.

        • cornshark@lemmy.world
          link
          fedilink
          arrow-up
          31
          ·
          3 hours ago

          Sudo makes you enter your password and docker doesn’t?

          • locuester@lemmy.zip
            link
            fedilink
            English
            arrow-up
            15
            ·
            2 hours ago

            Docker does by default - it only works if you use sudo. But the docs tell you to add yourself to the docker group (which requires sudo to do). Then running docker doesn’t require sudo anymore.

            • squaresinger@lemmy.world
              link
              fedilink
              arrow-up
              13
              ·
              2 hours ago

              Yeah, that’s a terrible decision in the docs. Don’t ever add a path where anything on the shell can execute user-modifyable code as root.

              As soon as you do that, you lose any protection that comes from separating root users and non-root users. Because now any malicious program can just use docker to elevate its code to root.

          • Zikeji@programming.dev
            link
            fedilink
            English
            arrow-up
            16
            ·
            2 hours ago

            Or don’t give your user docker and use sudo to use the docker CLI to get the same effect. Hell, you could even alias docker as sudo docker to get the same feel.

          • hperrin@lemmy.ca
            link
            fedilink
            English
            arrow-up
            3
            ·
            2 hours ago

            Only if you tell it to.

  • blarth@thelemmy.club
    link
    fedilink
    arrow-up
    43
    ·
    3 hours ago

    Podman will save us from the Terminators.

    • craftrabbit@lemmy.zip
      link
      fedilink
      arrow-up
      27
      ·
      3 hours ago

      I remember when I first needed to run containers I specifically went with podman because it doesn’t require root access out of some vague fear that docker can be exploited to break my stuff. I feel validated.

Programmer Humor@programming.dev

programmer_humor@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !programmer_humor@programming.dev

Welcome to Programmer Humor!

This is a place where you can post jokes, memes, humor, etc. related to programming!

For sharing awful code theres also Programming Horror.

Rules

  • Keep content in english
  • No advertisements
  • Posts must be related to programming or programmer topics
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 1.26K users / day
  • 4.48K users / week
  • 8.37K users / month
  • 17.5K users / 6 months
  • 1 local subscriber
  • 31.6K subscribers
  • 1.3K Posts
  • 25.4K Comments
  • Modlog
  • mods:
  • adr1an@programming.dev
  • Feyter@programming.dev
  • BurningTurtle@programming.dev
  • Pierre-Yves Lapersonne@programming.dev
  • BE: 0.19.5
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org