ntn888@lemmy.ml to Selfhosted@lemmy.worldEnglish · 1 year agoMy take on Alpine as a platform for selfhostingsimplycreate.onlineexternal-linkmessage-square5linkfedilinkarrow-up18arrow-down120
arrow-up1-12arrow-down1external-linkMy take on Alpine as a platform for selfhostingsimplycreate.onlinentn888@lemmy.ml to Selfhosted@lemmy.worldEnglish · 1 year agomessage-square5linkfedilink
minus-squareoshu@lemmy.worldlinkfedilinkEnglisharrow-up4·1 year agoKeeping containers up to date for security and bugfixes is just as important as OS packages.
minus-squarentn888@lemmy.mlOPlinkfedilinkEnglisharrow-up1arrow-down4·1 year agoyeah, but any update failure of a container is less fatal. and only affects the isolated service… it’s way easy to manage this situation than an unbootable server.
minus-squareoshu@lemmy.worldlinkfedilinkEnglisharrow-up3·1 year agoHow so? if I compromise a containerized app I get all the data that app has access to. From a security standpoint, each and every container running actually increases the potential attack surface.
Keeping containers up to date for security and bugfixes is just as important as OS packages.
yeah, but any update failure of a container is less fatal. and only affects the isolated service… it’s way easy to manage this situation than an unbootable server.
How so? if I compromise a containerized app I get all the data that app has access to.
From a security standpoint, each and every container running actually increases the potential attack surface.