Hacker News new | ask | show | jobs
by robryk 4038 days ago
Why is this distributed as a docker container?

Also, their README asks sers to pull their container from index (with no guarantee that it corresponds to the repo and, last I've checked, no real integrity guarantees stronger than "it's coming over ssl from docker.org") and then run it while giving it write access to /etc and command access to the docker daemon. This seems tome to be a very insecure way of starting a process that's not supposed to alter anything.

1 comments

Because that's their kool-aid.
I can't believe this didn't occur to me earlier, but when you think about it, docker containers are like ... "aaS"-aaS!
I see a lot of hype about Docker these days, with very little concrete evidence of benefits.