You have to make sure you're not putting any secrets in the container environment.
You have to make sure you're not putting any secrets in the container environment.
The reality here is this is the sort of attack SELinux should be good at stopping (it's not because no one uses SELinux, the policies most commonly used don't confine the user profile in a useful way, and a whole bunch of tools love ambient credentials in environment variables).
How does this work exactly? containers still need env vars and access to databases and cloud environments. Without these the container is just useless isolated pod.
The image itself isn't the same image that the app gets deployed in, but is a portable dev environment with everything needed to build and run my apps baked in.
This comes with some nice side effects like being able to instantly spin up clean work environments on my laptop, someone elses, or a remote vm.
Its not going to stop attacks, but it will limit blast radius a lot.