Hi all !

As of today, I am running my services with rootless podman pods and containers. Each functional stack gets its dedicated user (user cloud runs a pod with nextcloud-fpm, nginx, postgresql…) with user mapping. Now, my thought were that if an attack can escape a container, it should be contained to a specific user.

Is it really meaningful ? With service users’ home setup in /var/lib, it makes a lot of small stuff annoying and I wonder if the current setup is really worth it ?

  • mel ♀@jlai.luOP
    link
    fedilink
    English
    arrow-up
    3
    ·
    1 day ago

    I guess I should define my threat model first. Your answer pulls me towards a single user though