Hacker News new | ask | show | jobs
by falcolas 3515 days ago
So, here's a concern for you: this provides for a severe security hole, since it has the ability to effectively run as root on any machine its connected to (a'la privileged mode, volumes, network, leaking secrets through environment variables). It might be worthwhile to find a way to mitigate that security hole, or add some serious access control restrictions.

I wouldn't be too surprised if your test cluster machines are frequently rooted.

1 comments

Thanks for the feedback ! We will indeed investigate any potential security holes. We're also working on AC restrictions at the moment.