Docker Compose reads your “.env” without opt-out
github.com
github.com
As an attacker, I would put a great deal of focus on attacking company’s registries on Docker Hub. They can’t have 2FA, so the work/reward ratio is quite high.
Not everyone makes/uses software where the software itself is secret.
And there are plenty of uses for using proprietary images. For example, I have done workflows where the properitary code is layered on top of open-source code. (Although if I were to redo those CI/CD pipelines again, I would use the de-facto buildpack standard instead; even then, the buildpack slug itself would be properitary and requires an artifact store of some kind).
Either way, using GCP or AWS registry that integrates with their IAM systems works well. The newer versions of docker contains a plugin system, so both GCP and AWS command line tooling can hook in their own authentication mechanisms in there.
If I can push changes to your 'prod' tagged image, I'm going to have a very good time.
I have used them. It isn't that much of a hardship if you are already cloud native.
Companies with legacy or hybrid infrastructure may need to jump through additional hoops.
Unfortunately though docker hub really is a dumpster fire of a service, otherwise I'd have no problem just using their private repo features. However there are so many problems with that site that it's easier just to jump to AWS ECR or Github's new service.
(e.g I’ve had a few where a ruby image switched from Debian 9 to Debian 10, on most of the labels. It broke a lot of stuff and you just had to guess that they kept the old version on its own label, because Docker Hub didn’t say anything about it.)
The way people tackle their dependencies inside docker is utterly irresponsible.
Oh god please no.
TOTP isn't that difficult to set up. I'll even help make it happen. Don't use SMS for 2FA.
Why am I being downvoted?
I'm literally willing to volunteer days of my time, unpaid, to prevent SMS 2FA in favor of something more secure (i.e. TOTP).
I can't speak for all of those who downvoted you, but the comment you responded to mentioned how SMS based 2FA would be better than what they do today (i.e. nothing).
This is a fact. SMS 2FA, regardless of how bad it is, is still another hurdle an attacker would have to overcome. An additional hurdle, no matter how small, is still better than nothing at all. Therefore the assertion that SMS 2FA would be better than what they do today is simply an irrefutable fact.
If you left off the "Oh god please no." portion of your comment, you may not have been downvoted.
The corollary to don't let the perfect be the enemy of the good is don't let the barely better be the enemy of the substantially better.
Seriously auth over sms should not only be froned upon, but illegal. It is a nice cover you ass for the site that does it, but if you do 2f any way that is not using a uf2 physical token you should not be allowed near a computer.
Plus it works on a locked down intranet. Just don’t forget to run ntp!
1: https://cloud.google.com/community/tutorials/docker-compose-...
Do you use Docker-in-Docker or do you mount the docker socket inside your docker-compose container?
Oh dear god .. it's Docker all the way down.
I'd love to go straight to containerd or even basic linux containers but I'm not willing to run kubernetes on my personal machine and haven't found any ergonomic enough ways to run containers.
microk8s might not give as much gains.
k3s from Rancher actually cuts out a lot of code, and from I hear, can run fine on Rapsberry Pis.
I have not heard of "kind", but neat.
KIND - Kubernetes In Docker
Like docker (uses CRI images) but daemonless.
I was in a different dir to the docker-compose.yml file and launched docker-compose with the -f filename option and could not get .env to load.
https://github.com/sumdog/bee2
It has unit tests, but not a lot of good errors messages and is pretty specific to the stuff I host. I'm glad I did it though; great learning experience around the Docker API and how the internals of the Docker Engine work. I still use it to maintain all my self-hosted sites and tooling.
There are a lot of good libraries around the Docker API for Ruby, Python, Java/Scala, etc. If you're on a green field project setting up your local docker environments, and have the time, I'd almost suggest trying to build your own tooling from scratch rather than leveraging docker-compose at this point.
I use Docker Compose and Traefik (for routing) and self hosted a bunch of stuff given that most self hosting programs have some type of Docker support.
Would CNAB work with a custom provisioner, or would support for that need to be coded in?
Any system that reads `.env` files usually allows some way to specify the exact file to be read.
Rename .env to something else and reconfigure autoenv.
The workaround that I've found for this problem is to set "AUTOENV_ENV_FILENAME=.env.user" and then inside the project folder, I'm now using ".env.user" instead of just ".env".
I'll use this hack until Docker guys fix Docker Compose.
function lenv {
if [ -f '.env' ]; then
source .env
fi
}
function cd { builtin cd $@; lenv; }> docker-compose --env-file /dev/null
will get it to not read a .env file.
Will test later/tomorrow.
But the attitude runs all the way through docker products: arbitrary decisions made for their benefit with no thought to the externalities.
I can honestly say this exact issue is impossible for anyone who POUPZ. If you haven't tried POUPZ in production, or even POUPZ at home, my recommendation is to give it a try.
I think you'll be pretty glad for once that you POUPZ where you eat.