Windows in a Docker Container
github.com
github.com
“devices:
- /dev/kvm”
Well yeah, sure, you’re running a qemu vm in a container, that’s not exactly the same thing here.No one will (should) ever expose /dev/kvm to containers in production.
Docker is actually great for that kind of applications, because you can run it everywhere: Mac, Windows with one single-line. The only problem is that it's not very convenient to use docker images just as file containers, but it works.
If "running a VM" is somehow simpler with docker, you should really think about what Docker is supposedly doing for you.
A lot of the things that ran in Windows Nano Server worked even better in Linux containers, and a full Windows Server Core container is usually only necessary for .NET Framework, where you will need all of the luck in the world help you with that problem.
Packer and Ansible are also much harder to use for Windows Containers, so if you're already using those to configure VM images and Ansible to perform config mgmt on VMs, get ready for some headaches to make that work against Windows Containers.
Second, Yea, it's only use is Windows specific languages like .Net Framework and various Win32 API applications. Windows Containers works well enough if you are good enough with Powershell to handle various levels of bullshit that comes Windows.
You can build Linux containers just fine with Packer/Ansible. But to your point I already stated why I use Ansible and Packer for container images: "if you're already using those to configure VM images and Ansible to perform config mgmt on VMs"
I currently build a number of images with Packer and Ansible across Linux and Windows. I choose not to rewrite all of that from scratch in a crummy Dockerfile when I can just have Packer and Ansible make the images alongside everything else they're already making.
FROM scratch
COPY --from=qemux/qemu-docker:4.14 / /
Is this different than the following? FROM qemux/qemu-docker:4.14If a layer creates a file and then a subsequent layer deletes it, the deleted file is still present in the image taking up space. If you squash the layers, the deleted file is gone
“scratch” used to be an empty layer, but in newer versions is now just syntax to state that you want a layer without a parent layer
I don’t see any benefits. Security scanners have a harder time to track issues, because they can’t just detect the image is depending on an insecure base image.
It also strips the possibility to deduplicate some base layers, or a partial pull if you already have one of the base layers in the cache (Debian or Ubuntu are very common, you might have even the exact same version already in the layer cache).
Not a bad way to do penetration testing or sandbox a potential worm or malware.
It is pid remapping etc.. and any other features that even approximate a sandbox are from secomp, apparmor, /proc masking etc...
Namespaces not being jails or sandboxes is an important concept.
But it is really about the order namespaces start with almost no isolation and you add whatever you want.
Sandboxes and Jails tend to start more restricted by default.
As an example here is an older step by step example of the above. Note how disabling privileged containers at the docker server layer is still not possible as they decided user namespaces were their solution.
https://stackoverflow.com/questions/36425230/privileged-cont...
With containers, there is a responsibility for both the instantiation and the container image to ensure that isolation happens.
That is why I hesitate to consider them equal as the responsibilities are different.
From the README:
> Is this project legal?
> Yes, this project contains only open-source code and does not distribute any copyrighted material. Neither does it try to circumvent any copyright protection measures. So under all applicable laws, this project would be considered legal.
From install.sh:
if [[ "${VERSION,,}" == "win7x64" ]]; then
DETECTED="win7x64"
VERSION="https://dl.bobpony.com/windows/7/
en_windows_7_enterprise_with_sp1_x64_dvd_u_677651.iso"
fi
Along with other similarly shady links.Look, IANAL, nor am I hooting and hollering for Microsoft's profits. But that README seems dishonest, any competent user should be suspicious of a "bobpony"-distributed Windows ISO.
Agree that this should be in the documentation, but you can get into legal trouble if you directly link against microsoft.com in distributed code or binaries.
AFAICT this software would solve all its legal problems[1] if it replaced these hard links to clearly unlawful websites with user variables, $URI_TO_WIN10ISO or something. The fact that the README is basically lying to its users makes things even worse. I would go so far as to call this malware.
[1] In the sense of "successfully foisting legal difficulties onto end users"
Unless what you're saying is that this is a modified ISO to remove activation.
if thats the case then, I agree wholeheartedly. Just explaining why you dont/cant use the standard microsoft.com links.
I'm pretty sure these ISOs are NOT modified though I am a bit skeptical of some of these sources. Editing my first comment to clarify that I misread this...
Why the hell are we trying shitty workarounds to dockerizing Windows? It's all dumb legal crap we have to work around... All the while, there's this Linux thing that just works.
And you usually don't actually need Windows. It's an application ON windows you need. So, try Linux/wine docker and dockerize it in WINE.
I'm not searching for the exact wording, but hosting for an unlimited and unrestricted access is a distribution in a legal sense and is not allowed
Nothing the client is doing is unlawful afaict; I would prefer it if it was documented and easy to swap out the URL.
FWIW I had this exact issue when using vagrant/packer and it was always painful because we couldn’t target windows ISOs easily but equally we didnt want to self-host them on a public repo because of the dubious legality and negative speculation as we’re discussing here.
Those bobpony ISOs could be backdoored even if they’re not breaking laws for the client user. Would be good to walk through the legal way to generate the download link.
Nor I insisted or implied anything. Just something from my memory through the years of similar problems of the dubious legality of tools to ease the day to day tasks for people.
> Would be good to walk through the legal way to generate the download link.
There is a proper way, just like you said: an easy way to inject http/s URI. Hosting a bunch of ISOs is a solved problem, objectively even easier than hosting a Docker registry.
Glad we agree. :)
If you dont provide an URL they are automaticly downloaded from the Microsoft servers using this script: https://github.com/ElliotKillick/Mido It generates a completely legal download link automaticly.
And those bobpony ISOs for versions that the above Mido script does not support are all unmodified retail versions. I checked their SHA256 checksums, and I would invite anyone with doubts to do the same.
So I googled the key to see if it was a widely circulated known cracked key I found.
It turned up on this site: https://www.windowsafg.com/keys.html which implies (strongly) that its a placeholder key that doesn't activate windows, they’re used for installation only.
So for those I had to use an alternative mirror (BobPony), but I checked all the SHA256 checksums to make sure they are unmodified retail versions. If someone does not trust it, they can check the checksums of the downloaded ISO themselves or just dont use this container for anything below Windows 8.1.
Bonus if it can be a different architecture from the host machine.
>Safari 5.1.7 for Windows, released in 2010 and now outdated, was the last version made for Windows. https://support.apple.com/en-us/102665
But all of you are right. The safari version that i tested don't even support arrow functions.
You can get much more recent Safari (and iOS simulator Safari) releases through macOS virtualization, https://github.com/sickcodes/Docker-OSX though this skirts some Apple EULAs. If you want desktop Webkit rendering and JS interpreter parity, https://webkit.org/downloads/ also offers several Linux webkit browser options that would also likely be more accurate than Safari v5.