Capabilities on executables
Note on Linux Kernel capabilities
File capabilities allow users to execute programs with higher privileges. Best example is network utility ping
.
containers, programming, golang, hacks, kubernetes, productivity, books
Note on Linux Kernel capabilities
File capabilities allow users to execute programs with higher privileges. Best example is network utility ping
.
The easiest way to prove that root inside the container is also root on the host
Here are simple steps that you can follow to prove that the root
user inside container is also root
on the host. And how to mitigate this.
Instead of polluting your PATH the easier way to put project specific scripts
There are always scripts that you write to automate some mundane tasks. And then you put that script in a directory that is in your PATH
. But what this does is that it pollutes your system global PATH
and shows up in places you wouldn’t want it to be in.
No docker cp needed to copy files from host to your container
This blog shows you how you can copy stuff from your host machine to the running container without the docker cp
command that we usually use.