Docker is definitely not one of them. But LXD for example uses unprivileged containers by default and can be hardened with additional software for syscall filtering
Docker is definitely not one of them. But LXD for example uses unprivileged containers by default and can be hardened with additional software for syscall filtering
You also described docker.
I agree that docker's main focus isn't to be a security oriented sandbox, but perhaps you need to find a different wording of what exactly makes LXD (or others) so different.
Can docker do secure multiuser?
I think the reality is just that containers will always be imperfect, and you should understand that risk when building systems.
There's some documentation on how only trusted users should be given access to the docker daemon, but I do not consider it sufficient. At no point in the installation or getting started documents [0,1] is it mentioned that it drives a gaping hole through existing security measures. Instead, the mention was on the security page, three sections down in a discussion about the attack surface [2]. This is the sort of issue that should be in big bold blinking letters at the top of every tutorial, that access to docker is
I know that rootless docker exists and improves this situation, but it is neither the default behavior, nor the introductory example in official documentation. I know that docker's primary role is dependency management, and that it only considers escalation coming from within the container as security issues. But there's a world of difference between "I'm not a locksmith, so I don't sell locks." and "I'm not a locksmith, so I break in your windows." One is ambivalent to existing security measures, while the other, like Docker, actively subverts them.
[0] https://docs.docker.com/get-started/
[1] https://docs.docker.com/engine/install/
[2] https://docs.docker.com/engine/security/#docker-daemon-attac...
Edit: When I was initially researching this, because I was absolutely floored that this security flaw was even a possibility in something as widely used as docker, I came across this reddit post [3], which explains the issue quite well. It is 4 years old and predates rootless docker, but is still accurate to the default and most widely used behavior.
[3] https://www.reddit.com/r/docker/comments/7y2yp2/why_is_singu...