ntn888@lemmy.ml to Selfhosted@lemmy.worldEnglish · edit-22 months agoMy take on Alpine as a platform for selfhostingsimplycreate.onlineexternal-linkmessage-square5fedilinkarrow-up14arrow-down110
arrow-up1-6arrow-down1external-linkMy take on Alpine as a platform for selfhostingsimplycreate.onlinentn888@lemmy.ml to Selfhosted@lemmy.worldEnglish · edit-22 months agomessage-square5fedilink
minus-squareoshu@lemmy.worldlinkfedilinkEnglisharrow-up0·2 months agoKeeping containers up to date for security and bugfixes is just as important as OS packages.
minus-squarentn888@lemmy.mlOPlinkfedilinkEnglisharrow-up0arrow-down2·2 months agoyeah, but any update failure of a container is less fatal. and only affects the isolated service… it’s way easy to manage this situation than an unbootable server.
minus-squareoshu@lemmy.worldlinkfedilinkEnglisharrow-up1·2 months agoHow so? if I compromise a containerized app I get all the data that app has access to. From a security standpoint, each and every container running actually increases the potential attack surface.
Keeping containers up to date for security and bugfixes is just as important as OS packages.
yeah, but any update failure of a container is less fatal. and only affects the isolated service… it’s way easy to manage this situation than an unbootable server.
How so? if I compromise a containerized app I get all the data that app has access to.
From a security standpoint, each and every container running actually increases the potential attack surface.