LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-03-2014, 08:16 AM   #1
mike acker
Member
 
Registered: Feb 2014
Location: Michigan
Distribution: Debian 10
Posts: 199

Rep: Reputation: Disabled
Docker -- any interest or experiences


I've been reading a bit on "Docker"

I ran into Docker reading this article on CoreOS

it immediately piqued my interest: an application program ("app", for short) -- should run on an O/S seeing in its environment only itself

it will be interesting to find out if Docker can be profiled to restrict/limit access to resources-- file directories, network I/O, and such

theoretically DOCKER should be able to run every app as though each app were run using a separate TAILS thumb-drive O/S
 
Old 11-04-2014, 08:12 PM   #2
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,323
Blog Entries: 28

Rep: Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142
I've heard it compared to BSD "jails" for Linux, but I have no experience with it. It seems to be the new cool toy.

A web search for "docker linux" will turn up many articles.
 
Old 11-06-2014, 10:18 AM   #3
mike acker
Member
 
Registered: Feb 2014
Location: Michigan
Distribution: Debian 10
Posts: 199

Original Poster
Rep: Reputation: Disabled
to me, the Real Issue with a Studio Workstation (aka "Desktop PC") is that when the owner logs on his|her credentials are then used by every app program launched. you might want to control access to a finer degree: for example you might want to restrict your web browser to accessing only the /Documents area and excluding the /Documents/Correspondence area .

this I understand can be done using AppArmor provided the user can and will make the effort to edit the access control profile. JavaScript isn't supposed to go ferreting around your directories anyway, but-- "WebApps" have been gaining a lot of steam lately

I fiddled around using AppArmor when I was using Ubuntu 12.04LTS but it was hard to really understand the profiles that were generated. a good GUI editor for AppArmor profiles would be great.

one of these days I gotta figure out how to write GUI stuff in C ...
 
Old 11-06-2014, 11:12 AM   #4
grzesiek
LQ Newbie
 
Registered: Nov 2010
Location: Poland
Distribution: Debian
Posts: 20

Rep: Reputation: 0
Docker is a next steps from LXC (cgroups). It is nothing different as LXC via libvirt and some additions/automations.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Docker Founder Explains What Docker is all About LXer Syndicated Linux News 0 08-21-2014 09:20 PM
This may be of interest to UK drivers baldy3105 General 2 01-27-2006 03:44 AM
Out of interest... gwejones Linux - General 1 09-13-2005 03:45 AM
A little story, probably of no interest... Looking_Lost General 21 06-25-2005 03:57 AM
Need to keep interest in linux mikeymorgan Linux - Newbie 18 03-27-2005 07:38 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:44 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration