Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
da_667
da_667
@da_667@infosec.exchange  ·  activity timestamp 14 hours ago

dockerfiles are just installer shell scripts with more steps.

Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
  • Copy link
  • Flag this post
  • Block
rj
rj
@arrjay@tacobelllabs.net  ·  activity timestamp 13 hours ago

@da_667 docker is just *tar* with more steps

  • Copy link
  • Flag this comment
  • Block
Risotto Bias
Risotto Bias
@risottobias@toot.risottobias.org  ·  activity timestamp 12 hours ago

@arrjay @da_667 yup

ip netns add // iptables -t nat...
unshare --mount --uts --net --ipc --pid --cgroup --fork...
ip netns exec mynet chroot ./container
mount -t proc proc /proc ... sys, tmpfs...
cgcgreate -g "thing"
cgexec -g "group" ... netns... unshare... chroot...
nsenter...

:3

  • Copy link
  • Flag this comment
  • Block
I love this, so I
I love this, so I
@jpm@aus.social  ·  activity timestamp 14 hours ago

@da_667 and shoved behind a NAT for some bizarre reason

  • Copy link
  • Flag this comment
  • Block
Dave
Dave
@davedave@aus.social  ·  activity timestamp 13 hours ago

@jpm @da_667 i wasn't there at the beginning, but I'm willing to bet someone noisy "solved" networking by keeping it simple by staying with OSI layer 3

  • Copy link
  • Flag this comment
  • Block
da_667
da_667
@da_667@infosec.exchange  ·  activity timestamp 14 hours ago

@jpm VMs, but worse in every conceivable way.

  • Copy link
  • Flag this comment
  • Block
Site Reliability Enby (&)
Site Reliability Enby (&)
@SiteRelEnby@transfem.social  ·  activity timestamp 13 hours ago

@da_667@infosec.exchange @jpm@aus.social

...why? docker containers don't need patch management (past just "do you have a gitops workflow?" - no config management etc) or log aggregation from multiple sources or DNS config or to run 700 pieces of systemd shit just to start up.

  • Copy link
  • Flag this comment
  • Block
I love this, so I
I love this, so I
@jpm@aus.social  ·  activity timestamp 13 hours ago

@SiteRelEnby @da_667 ahahahahahahahahahaha!

  • Copy link
  • Flag this comment
  • Block
I love this, so I
I love this, so I
@jpm@aus.social  ·  activity timestamp 13 hours ago

@SiteRelEnby @da_667 (i'm guessing you were being sarcastic? all of those things are a sign of a mature production operations environment)

  • Copy link
  • Flag this comment
  • Block
I love this, so I
I love this, so I
@jpm@aus.social  ·  activity timestamp 14 hours ago

@da_667 it’s like the LinuxBros saw Solaris Zones and FreeBSD Jails and decided they didn’t want anything to do with actually designing and engineering a userspace virtualisation layer so they slapped together whatever shit they happened to have in their hands and called it an “improved development experience”

  • Copy link
  • Flag this comment
  • Block
Dave
Dave
@davedave@aus.social  ·  activity timestamp 13 hours ago

@jpm @da_667 it was never an improvement dev experience, but it was 1000 times easier for the sysadmin to figure out what dumb shit the dev had done to make it "just work" in Docker

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.2-alpha.32 no JS en
Automatic federation enabled
Log in
Instance logo
  • Explore
  • About
  • Members
  • Code of Conduct