frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Securing Services with Rootless Containers

https://blog.coderspirit.xyz/blog/2026/07/06/securing-services-with-rootless-containers/
9•speckx•4d ago

Comments

ranger_danger•49m ago
Personally I still think this is not enough, and we really need full generalized (not AI-only) microvm support built into docker/podman, like yesterday.

Currently it's difficult to even get a hold of a properly configured minimal kernel (or time-consuming to try to build one) and all the right command-line incantations to even start a one-off microvm using say, qemu, with all the proper storage/networking/etc. bits one needs for production environments. Plus you need to keep that kernel updated very regularly.

I know there's projects like smolvm that try to make this simpler, but I've had some major problems with those solutions as well, and I just feel like the big boys need to step up and support this directly by now.

eyberg•21m ago
Containers and security are oxymorons. The flood of page cache cves (which can always be escalated/weaponized to an escape) from the other month is making deploying containers to prod untenable.

As for orchestration - a lot of folks think you need a completely new orchestration system for dealing with vms but we just simply re-use the existing infrastructure that already exists - the public clouds. Those companies have tens of thousands of engineers that are much better than the average engineer at this stuff, custom hardware, custom protocols and close to several decades of existing deployment.

I can build and ship a vm from my laptop/ci to prod on AWS/GCP in ~tens of second. Granted I come from the camp that thinks deploying full blown general purpose operating systems to prod is an increasingly incredibly risky practice.

burakemir•9m ago
Maybe this here helps (I have not tried yet): https://github.com/virtkit-dev/virtkit
kayson•42m ago
I'd still rather use docker. I don't mind that the daemon runs as root because there are some things that you need root for anyways! Like binding to privileged ports or setting up networks (use `internal: true` and the daemon will automatically set up iptables rules that limit traffic).

I deploy docker compose files with ansible so everything comes with built in security defaults like rootless, dropped caps, no new privileges, etc. I wish more containers supported running read only (its usually pretty easy to add, just overlooked) and distroless (common for go apps, less so otherwise).

There was a pretty good comment on reddit a while back with a list of hardenings for compose files [1]

1. https://www.reddit.com/r/selfhosted/comments/1pr74r4/comment...

seemaze•26m ago
The '--userns=auto' argument is a useful isolation method in both rootless and rootful Podman containers. This allows rootful Podman to orchestrate privileged capabilities while running the container processes in an unprivileged namespace.

See the discussion here:

https://github.com/podman-container-tools/podman/discussions...

Watching Go's new garbage collector move through the heap

https://theconsensus.dev/p/2026/07/19/observing-gos-garbage-collector-old-and-new.html
111•matheusmoreira•2d ago•8 comments

Launch HN: Rise Reforming (YC S26) – Turning Waste Gases into Valuable Chemicals

https://www.rise-reforming.com
31•george_rose25•1h ago•8 comments

Self-contained highly-portable Python distributions

https://gregoryszorc.com/docs/python-build-standalone/main/
66•jcbhmr•2h ago•15 comments

Ray tracing massive amounts of animated geometry using tetrahedral cages

https://gpuopen.com/learn/ray-tracing-massive-amounts-animated-geometry/
30•LorenDB•4d ago•3 comments

Glue bonds to nonstick surfaces and wipes clean with ethanol

https://cen.acs.org/materials/adhesives/glue-bonds-nonstick-surfaces-wipes-clean/104/web/2026/07
122•gmays•4d ago•61 comments

The computer that helped win World War II

https://spectrum.ieee.org/colossus-computer-ieee-milestone
142•baruchel•5d ago•62 comments

Bytecode-to-Source Mapping

https://tidefield.dev/bytecode-to-source-mapping/
25•evakhoury•3h ago•1 comments

Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

https://eaton-works.com/2026/07/27/my-eicher-hack/
103•EatonZ•6h ago•29 comments

Judge Rejects Google's Attempt to DMCA Its Way Out of Being Scraped

https://www.techdirt.com/2026/07/27/judge-rejects-googles-attempt-to-dmca-its-way-out-of-being-sc...
158•cdrnsf•3h ago•59 comments

Securing Services with Rootless Containers

https://blog.coderspirit.xyz/blog/2026/07/06/securing-services-with-rootless-containers/
12•speckx•4d ago•5 comments

Show HN: FeyNoBg – Automatic background removal model and training library

https://usefeyn.com/blog/feynobg/
65•snyy•4h ago•20 comments

MAI-Cyber-1-Flash inside MDASH

https://microsoft.ai/news/introducing-mai-cyber-1-flash-inside-mdash/
196•migmartri•4h ago•106 comments

Kimi-K3 on HuggingFace

https://huggingface.co/moonshotai/Kimi-K3
1263•nateb2022•15h ago•489 comments

Removing React.js from the codebase and adapting Htmx for UI interactivity (2023)

https://misago-project.org/t/removing-reactjs-from-the-codebase-and-adapting-htmx-for-ui-interact...
196•Ralfp•11h ago•143 comments

UpCodes (YC S17) is hiring remote AE's to help make buildings cheaper

https://up.codes/careers?utm_source=HN
1•Old_Thrashbarg•4h ago

Paged Out #9 [pdf]

https://pagedout.institute/download/PagedOut_009.pdf
133•laurensr•7h ago•18 comments

Libsm64: Mario 64 as a library for use in external game engines

https://github.com/libsm64/libsm64
160•klaussilveira•11h ago•19 comments

Platform engineering 2.0 mitigates AI security and compliance risks

https://platformengineering.org/blog/how-platform-engineering-2-0-mitigates-ai-security-and-compl...
3•CrankyBear•1h ago•0 comments

How is the Bun Rewrite in Rust going?

https://lockwood.dev/ai/2026/07/27/how-is-the-bun-rewrite-in-rust-going.html
410•tomlockwood•10h ago•314 comments

VLC for Unity now supported on Linux

https://code.videolan.org/videolan/vlc-unity
141•martz•12h ago•39 comments

Show HN: Let's Seal – Let's Encrypt for document signing, free and self-hosted

https://github.com/letsseal/letsseal
47•nsokin•5h ago•22 comments

Tokio Gives Progress, Not Ordering: Scheduling 1M Tasks

https://pranitha.dev/posts/tokio-gives-progress-not-ordering/
25•pranitha_m•6h ago•0 comments

How real are real numbers? (2004)

https://arxiv.org/abs/math/0411418
28•surprisetalk•5h ago•17 comments

First Robotic Satellite Servicer Launched

https://www.nrl.navy.mil/Media/News/Article/4551871/robotic-servicing-of-geosynchronous-satellite...
71•GlenTheMachine•4d ago•41 comments

Towards a Theory of Bugs: The Ruliology of the Unexpected

https://writings.stephenwolfram.com/2026/07/towards-a-theory-of-bugs-the-ruliology-of-the-unexpec...
58•nsoonhui•3d ago•30 comments

The Artist Who Colored Ghibli

https://animationobsessive.substack.com/p/the-artist-who-colored-ghibli
66•herbertl•3h ago•4 comments

Modern email can be built from borrowed parts

https://en.andros.dev/blog/d7ed8b07/modern-email-can-be-built-from-borrowed-parts/
156•andros•13h ago•89 comments

Decathlon Germany adds Wero payment option to decathlon.de website

https://www.sgieurope.com/e-commerce/decathlon-germany-launches-wero-payment-on-its-website/12239...
279•doener•4h ago•189 comments

Should you wash your solar panels?

https://incoherency.co.uk/blog/stories/should-you-wash-your-solar-panels.html
212•surprisetalk•8h ago•199 comments

Forth

https://xkcd.com/3277/
12•beardyw•1h ago•3 comments