frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: Why not just running OpenClaw in Docker?

1•fdeage•1h ago
Everyone in town is talking about running OpenClaw/Clawd on a VPS or a dedicated burner machine (e.g. a Mac mini), for obvious security reasons.

What I don't see discussed much is Docker. On macOS it already runs inside a Linux VM, and the setup can hardened even more (in principle): no bind mounts, no /var/run/docker.sock, non-root user, read-only filesystem, tight resource limits, restricted networking, etc.

Given that, what are the concrete reasons people still consider Docker unsafe?

Comments

rvz•1h ago
> Given that, what are the concrete reasons people still consider Docker unsafe?

Docker shares the same kernel as the host and is at risk of allowing container escapes and all it takes is for it to be exploited at the kernel level. [0]

As long as you run Docker on the host (which doesn't provide kernel isolation), the host will always be at risk of container escapes.

[0] https://www.sysdig.com/blog/runc-container-escape-vulnerabil...

fdeage•1h ago
Thanks, that makes sense in general. Do you know if these vulnerabilities have actually been exploited in the wild?

(also, on macOS specifically, Docker runs inside a Linux VM, so the shared kernel is the VM's kernel, not the host's. Are there known escapes from containers to Docker Desktop VM to macOS host?)

Properly securing Open law with authentication

https://www.haproxy.com/blog/properly-securing-openclaw-with-authentication
1•owenthejumper•2m ago•0 comments

Open Source, Python and AI Are Shaping the Data Future (With Wes McKinney) [video]

https://www.youtube.com/watch?v=SMgUDZ9xkHM
1•tosh•3m ago•0 comments

Show HN: Prvue – Self-managed preview environments for back end apps

1•dan_le_brown•5m ago•0 comments

Ax for Browser Automation Platforms: Browserless vs. Browserbase vs. Anchor

https://techstackups.com/comparisons/browserless-vs-browserbase-vs-anchor-agent-experience/
1•sixhobbits•5m ago•0 comments

Show HN: Prvue – Self-managed preview environments for back end apps

https://docs.prvue.dev
1•dan_le_brown•7m ago•0 comments

Refuge, Signals, and the Things We Forgot

https://aleger.substack.com/p/refuge-signals-and-the-things-we
1•aleger•12m ago•0 comments

Easily write Bash with a transpiler [video]

https://fosdem.org/2026/schedule/event/GGLZS9-amber-lang-bash-transpiler/
1•birdculture•13m ago•0 comments

Claude Is a Space to Think

https://www.anthropic.com/news/claude-is-a-space-to-think
2•meetpateltech•13m ago•1 comments

The Maintenance of Everything

https://www.stripe.press/maintenance
2•MintyPyro•15m ago•0 comments

Show HN: OpenShears – I built an uninstaller because OpenClaw refuses to die

https://github.com/oswarld/openshears
1•haebom•16m ago•0 comments

The missed incident priority: The Near Miss

https://jensrantil.github.io/posts/near-miss-incidents/
1•JensRantil•17m ago•0 comments

Adobe Won't Discontinue Animate

https://www.theverge.com/tech/873621/adobe-animate-maintenance-mode-reverse-course
3•tambourine_man•19m ago•0 comments

Show HN: GitScrum – Full project management inside VS Code/Cursor/Windsurf

https://marketplace.visualstudio.com/items?itemName=gitscrum-vscode.gitscrum-vscode
1•renatomarinho•21m ago•0 comments

Understanding the Keep4o Backlash

https://arxiv.org/abs/2602.00773
1•50kIters•21m ago•0 comments

TonyPitony, Brain Rots, 67

https://poplit.hcommons.org/2026/02/03/tonypitony-brain-rots-67-contemporary-dada-and-our-rejecti...
2•jruohonen•22m ago•0 comments

Yarn 6 Preview

https://yarn6.netlify.app/blog/2026-01-28-yarn-6-preview/
1•vidyesh•22m ago•0 comments

Guthman Musical Instrument Competition (2026 Finalists)

https://guthman.gatech.edu/2026-finalists
1•latexr•24m ago•0 comments

The myth of the free market (2020)

https://www.nationofchange.org/2020/01/24/the-myth-of-the-free-market/
1•robtherobber•25m ago•0 comments

DayFlow: A Full Calendar Component for React

https://dayflow-js.github.io/calendar/
1•vidyesh•27m ago•0 comments

The Ghidra Book, 2nd edition

https://nostarch.com/ghidra-book-2e
1•0x54MUR41•27m ago•0 comments

China bans hidden car door handles, which can trap people after crashes

https://www.npr.org/2026/02/03/nx-s1-5698224/china-electric-car-door-handles
2•geox•27m ago•0 comments

Awesome Codex Automations

https://github.com/onurkanbakirci/awesome-codex-automations
1•onurkanbkrc•30m ago•0 comments

UN Open Sourcre Week 2026

https://www.unopensource.org/
3•jruohonen•32m ago•0 comments

The SpaceX mega merger boosts the Musk trade

https://finance.yahoo.com/news/the-spacex-mega-merger-boosts-the-musk-trade-110026592.html
1•01-_-•33m ago•0 comments

We Are the Art; Brandon Sanderson's Keynote [video]

https://www.youtube.com/watch?v=mb3uK-_QkOo
2•simplegeek•33m ago•0 comments

From Human Ergonomics to Agent Ergonomics

https://wesmckinney.com/blog/agent-ergonomics/
1•haraball•36m ago•0 comments

A Quick Introduction to OxCaml

https://noelwelsh.com/posts/a-quick-introduction-to-oxcaml/
1•noelwelsh•37m ago•0 comments

Bypassing Kernel32.dll for Fun and Nonprofit

https://ziglang.org/devlog/2026/#2026-02-03
1•Sh4pe•37m ago•0 comments

Show HN: Rust Monorepo Analyzer v0.16.0 and v0.17.0 faster scans and better TUI

https://github.com/bumahkib7/rust-monorepo-analyzer
1•bumahkib7•38m ago•0 comments

Elon Musk Has Grand Plans for Data Centers in Space. Experts Are Skeptical

https://uk.pcmag.com/networking/162953/elon-musk-has-grand-plans-for-data-centers-in-space-expert...
2•ironyman•39m ago•0 comments