|
|
|
|
|
by xmodem
45 days ago
|
|
I am aware, thank you :). I responded to a sibling dupe-comment over here [1]. To summarize, in my experience there is immense value to having basic shell tools available in the environment where you need them with zero extra friction. Stripping those out provides a security benefit only in specific nebulous and niche scenarios. 1: https://news.ycombinator.com/item?id=48561605 |
|
I agree, however assuming you maintain a chroot for debugging this can be accomplished with a shell command that takes a single argument to target a running container by name.
Your linked comment suggests being limited to kubernates but nsenter and a chroot are entirely runtime agnostic.