[gentoo-hardened] Re: docker updates

2015-02-27 Thread Alex Brandt
On Wednesday, February 25, 2015 22:11:55 Alex Efros wrote: > What is recommended way to update Docker containers with Gentoo? docker pull ${NEW_IMAGE} Somewhat sarcastic but actually true. I don't recommend running production applications inside of Gentoo based containers. I highly recommend

[gentoo-hardened] Re: docker updates

2015-02-27 Thread Alex Efros
Hi! On Fri, Feb 27, 2015 at 10:38:34AM -0600, Alex Brandt wrote: > Somewhat sarcastic but actually true. I don't recommend running > production applications inside of Gentoo based containers. This makes sense for Gentoo, but my question was CC: to this list not as off-topic, my host will be Har

Re: [gentoo-hardened] docker updates

2015-02-27 Thread eric gisse
Let's turn this around. What is the business case for containerization when security is so loose and ill-defined right now? On Thu, Feb 26, 2015 at 7:20 PM, Alex Efros wrote: > Hi! > > On Thu, Feb 26, 2015 at 11:35:34AM +0100, F. Alonso wrote: >> I agree with containers do not improve security.

Re: [gentoo-hardened] Re: docker updates

2015-02-27 Thread Jason Zaman
On Fri, Feb 27, 2015 at 08:04:52PM +0200, Alex Efros wrote: > Hi! > > On Fri, Feb 27, 2015 at 10:38:34AM -0600, Alex Brandt wrote: > > Somewhat sarcastic but actually true. I don't recommend running > > production applications inside of Gentoo based containers. > > This makes sense for Gentoo,

Re: [gentoo-hardened] docker updates

2015-02-27 Thread Sven Vermeulen
On Sat, Feb 28, 2015 at 3:58 AM, eric gisse wrote: > Let's turn this around. > > What is the business case for containerization when security is so > loose and ill-defined right now? The promise (and depending on your context and regulations, this might be true already as well) is that you can of