Hacker News new | ask | show | jobs
by kronin 2211 days ago
If the container is running as root, and you escape the container, you are root on the host.

Containers share the kernel with the host, and are only as isolated as the uid the process in the container runs as and the privileges you grant that container.

1 comments

He doesn't seem to understand the new landscape well enough to make his comparisons.

The point about AWS was not a Kubernetes comparison. It was a GCP one, because you asked what was wrong with the God aweful AWS