Spyke
containers·Container platforms (docker, lxc, podman)bymel ♀

Dedicated service user or not ?

Cross-posted from "Dedicated service user or not ?" by @[email protected] in ![email protected]


Hi all !

As of today, I am running my services with rootless podman pods and containers. Each functional stack gets its dedicated user (user cloud runs a pod with nextcloud-fpm, nginx, postgresql...) with user mapping. Now, my thought were that if an attack can escape a container, it should be contained to a specific user.

Is it really meaningful ? With service users' home setup in /var/lib, it makes a lot of small stuff annoying and I wonder if the current setup is really worth it ?

View original on jlai.lu
No comments on the original post yet.
Dedicated service user or not ? | Spyke