594 karma · joined March 7, 2022
1: https://www.reddit.com/r/FrutigerAero/comments/1k2ao9b/the_m...
I would also add to that affordable food is being first produced by agricultural machinery running on diesel, which is then transported by trucks running on diesel on roads build by machinery running on diesel. There is a good youtube video about this from channel driving 4 answers.
docker run -ti --rm --user 1000:1000 --privileged=false alpine:latest
~ $ cat /proc/sys/net/ipv4/ip_unprivileged_port_start
0
~ $ id
uid=1000 gid=1000 groups=1000
~ $ nc -lvp 80
listening on [::]:80 ...
Also the iptable rules Docker creates is for routing traffic to container with destination NAT, to actually limit traffic you have to do it yourself by inserting rules in DOCKER_USER chain.Found the LLM generated part.
For forward chain we set docker network ranges to route between themselves and only services actually used in containers. Allow container outgoing connections to our DNS servers, centralized HTTP proxy server and monitoring - nothing else containers are allowed to route to.
And for output is similar, only allow our DNS servers, NTP, HTTP proxy, centralized rsyslog where everything goes and zabbix monitoring server and a few icmp types - nothing else gets out and is logged.
With the advent of these supply chain attacks we read about often here it's just a matter of time some container is compromised and this seems like only viable way to at least somehow limit impact when such an event occurs.
What the hell are you talking about? They already know where my kids are! At school which is funded by government.