Hacker News new | ask | show | jobs
by popcorncowboy 1159 days ago
In case anyone's wondering, that gives the container root level access to the host's Docker daemon. A big potential security hole.
1 comments

It's also just generally wrong to build a scheduler on top of the docker API. We have CRI for a reason, because everyone knows Docker is not going to be around forever. Certainly not the company. Maybe dockerd.