Be Using Rootless Containers
22 days ago
- Docker's client-server architecture with a root-owned daemon creates security risks, especially when users add themselves to the docker group for convenience, enabling root escalation without authentication.
- A demonstration shows how a non-root user can mount the host filesystem in a container and access files as root, bypassing permission restrictions.
- Rootless alternatives include Docker's rootless mode (requires manual setup) and Podman, which is daemonless and runs containers under the user's own account, preventing root escalation.
- Podman has differences: it may not find images without fully qualified names, requires systemd integration for container restart after reboot, and offers an optional API service for compatibility with Docker tools.
- The author recommends rootless containers for better security and primarily uses Podman, noting that occasional Docker use on isolated VMs is acceptable when security is less critical.