Dockersh – a shell that puts users into individual docker containers
github.com
github.com
Funniest instance of this misused homonym I've seen.
I use it to work on my Mac, but develop on a Linux box:
Siphon does nothing but create and forward psuedoterminals, so it has a lot less features to directly interact with docker than dockersh appears to have, but it's also able to do its job without root or any priviledged syscalls, and doesn't rely on any knowledge of kernel namespaces at all. Which is more useful may depend on your perspective and usecases.
https://gist.github.com/TeMPOraL/3d134ce0d4a2b2f4232b
Basically, it starts a screen instance with a shell and your script running side by side, so when you Docker-attach to it, you can C-a " to shell.
run.sh would be the script you want to be run in container - the one that starts your webserver, database, whatever.
I adapted a screen solution from some random StackOverflow comment.
http://sandbox.libvirt.org/quickstart/
Libvirt sandbox can also put processes, jobs, users etc into real VMs as well as chroots ^W containers.
Even if you were saying that such a login shell already exists with another containerization scheme, the fact it uses Docker is relevant to those who are investing in Docker. For instance Dockersh can be configured to run the shell in a specific Docker image; that is you can re-use your existing knowlegde and tooling.
Or how we ISPs gave dialup modem users their own login shells in mid 1990's:
http://www.freebsd.org/cgi/man.cgi?query=jail
I can't find docs for the chroot shell we used back then, but what we did was along the same lines as this:
This is a fun alternative to proper jails but unfortunately, security wise this would not last very long on in a real world application.
Not going to lie, would be pretty cool to set something like this up and auto provision upon payment.
Yes, design is outdated. This was great at the time; people were still using tables for layouts.
http://l3net.wordpress.com/2014/04/16/how-to-restrict-a-logi...
Right now it is difficult. Docker doesn't support it directly. There is a lot of demand for it:
https://github.com/docker/docker/issues/1228
You have to use nsenter, which is OK, but requires additional installation:
https://github.com/jpetazzo/nsenter
It looks as though an-almost-but-not-quite-the-same thing will land in Docker at some point:
https://github.com/docker/docker/pull/7409
And this shell is another attempt to make a very useful feature available.
From reading the README file, it seemed to me it was only spawning a login shell process in a new container (not an existing one), and possibly resuming an existing container.
I know the phusion/baseimage argues against excessive isolation:
https://github.com/phusion/baseimage-docker#docker_single_pr...
No! Warning!
Docker is not secure and locked down. Do not use this for "security".