On Pausing Containers – how we built, and why we deprecated, our container paus
metalbear.co
metalbear.co
That sounds like an audit/compliance nightmare. For example, if the infrastructure is within scope of PCI-DSS you're making not just the developer's laptop, but all of the network they're on now part of the audit scope, and it all needs to be up to scratch for security.
Combine that with the risk of using it to sniff/exfiltrate PII etc. I'm astounded that this was even built as a feature. It's a hacker's best friend, surely?
If it's too hard to test your code, fix your test environments, don't make production, or test, come to your laptop.
all in all, this seems like a very sketchy way to deal with prod debugging. there's a reason cicd pipelines exist and why dev teams don't run prod services from their workstations.