I use AppArmour and use Podman rootless for everything that needs to be containerized so it's all good for me anyway :)
Fun read! Maybe put an RSS button somewhere so it's easier to subscribe to?
Fun read! Maybe put an RSS button somewhere so it's easier to subscribe to?
This is the way. Docker rootless and podman rootless. A lot less attack surface than running containers as root.
I haven't tried a dedicated user for this though. I'm sure that mounting volumes would get messed up.
Security is layers.