Weak that this isn't the default.
You should probably know about this workaround by now.
The tragedy is of course that when security and usability collide, 80/20 rule will apply where 80% of people will pick usability over security. I have worked with many with the title >= "Senior Engineers" who saw that page, read the explanation, and still had no idea what the ramifications of their changes were. "Yeah sure it said any user in the docker group will be able to get root on the host, but aren't containers isolated?"
(It sounds like you put it on an SSD on an extension cord and moved it to the kitchen or something.)
--cap-drop=ALL
--pids-limit=4096
--runtime=runsc> I noticed the machine doesn't have copy-fail patched, here is a quick workaround for not having root access for now.
> // TODO: find a better way to do this in the future.
alephnerd•59m ago
dangus•56m ago
unglaublich•53m ago
tempest_•41m ago
awoimbee•41m ago
oytis•52m ago
throwaway613746•36m ago
ssl-3•33m ago
SoftTalker•3m ago
alephnerd•49m ago