* Feature preview of digitally signed images
* Process injection with `docker exec`
* More flexible container lifecycle with `docker create`
* Shared directories on Mac OS X thanks to boot2docker
* Fine-grained security options
* Feature preview of digitally signed images
* Process injection with `docker exec`
* More flexible container lifecycle with `docker create`
* Shared directories on Mac OS X thanks to boot2docker
* Fine-grained security options
I can already see that `docker exec` and `docker create` will allow me to get rid of a number of admin and configurator containers.
When I started playing around with boot2docker, I was gagging for the ability to share directories with OS X. However, it turns out that I didn't really need that once I realised that caching means that building images is very fast.
https://github.com/docker/docker/blob/master/trust/trusts.go...
Ideally docker users could sign their own images and provide their own keys to do signature validations. What is the timeline on this work? With out this, "digitally signed images" means "locked into Docker, Inc- otherwise no security", and is very misleading.
A very basic implementation would be to read certs out of a directory on the filesystem and is how all other package managers handle this.
Edit: I missed the part in the post that even if the signature fails, the container still runs. The signatures do nothing. Got it. Preview.
The only reason we're starting with verification-only, and only for images produced by the official library maintainers, is because the other side of the tools (signing) are not yet ready to be merged in Docker. By releasing a subset now, we can start getting some feedback and ironing out the quirks, while the contributors finish their work on the signing tools, using the library maintainers as guinea pigs. Hope this helps.
PS. to state the obvious, all of this is taking place in the open on #docker-dev in Freenode. It is being designed by key contributors from multiple companies, and you are welcome to join the fun.