Comment on Portainer 3.0 is coming, and here's what it means for you — Portainer

<- View Parent
antheraeavx@slrpnk.net ⁨1⁩ ⁨week⁩ ago

You can run rootless Podman with Portainer, I do too.

Can you elaborate on the ways a home lab is less secure if it runs a container management GUI? I’m open to learning more about it. What additional permissions does a GUI inherently require?

Most companies I worked at used OpenShift in production, and I do not think it was considered an attack vector more than any other component of the ecosystem. I would be surprised if this was a factor when it came to security incidents.

I don’t think that container privilege escalation vulnerabilities are correlated to the use of a GUI. To me, it is not a significant (or otherwise unique) risk. Even less so when we’re talking about a home lab that is only accessible via a VPN.

source
Sort:hotnewtop