Conversely, if I were sysadmin at a bank I would most definitely be concerned what was running in my network.
Conversely, if I were sysadmin at a bank I would most definitely be concerned what was running in my network.
- docker containers were built from source
- Dockerfile published with the code
- Built in a new CI environment
- Pushed, Pulled and deployed from the sha
- Collecting network traffic, undertaking protective monitoring, that looks for those backdoors.
Just because you can pull arbitrary bullshit doesn't mean you have to.
Though for the record, the same sysadmins that whine about newer tools are generally the same ones that implicitly trust their older toolsets. Just because you can compile it, doesn't make it secure, so you need to be running monitoring solutions and hedging your bets no matter the tech.
I've worked at a bank. It's a docker file. Running Hadoop. On top of a Linux Container. Running in Rhel 5. On top of a vmware hypervisor.