Hacker News new | ask | show | jobs
by meirelles 3812 days ago
Yes. I agree with you. Have many other good uses for Docker. But I found LXC easier, as it's possible assign a public IP and let the chef mange the iptables/service discover exactly like a VM/baremetal. Docker drops almost all caps, which is great for security, but isn't possible a container manage his own isolated iptables.