mirror of
https://github.com/tiennm99/composes.git
synced 2026-10-11 03:13:16 +00:00
chore(code-server): mount the docker socket read-only
The flag does not restrict Docker API access; the README says so.
This commit is contained in:
1 parent
a82cfcc677
commit
3574c55e0a
2 files changed
+7
-1
No files matched your search
@@ -21,6 +21,12 @@ is the same `PASSWORD`) or add the group by hand. Handing a container the
|
||||
socket is equivalent to giving it root on the host -- that is accepted here
|
||||
because this is a single-user dev box.
|
||||
|
||||
The mount carries `:ro`, which is not a security boundary: it only marks the
|
||||
socket file read-only, while the Docker API is reached by connecting to the
|
||||
socket, which a read-only mount does not stop. Full API access, and with it
|
||||
root on the host, remains. Restricting that would need a socket proxy or a
|
||||
separate rootless daemon.
|
||||
|
||||
## Environment
|
||||
|
||||
| Variable | Purpose |
|
||||
|
||||
@@ -20,6 +20,6 @@ services:
|
||||
- PWA_APPNAME=code-server
|
||||
volumes:
|
||||
- 'code-server-config:/config'
|
||||
- '/var/run/docker.sock:/var/run/docker.sock'
|
||||
- '/var/run/docker.sock:/var/run/docker.sock:ro'
|
||||
volumes:
|
||||
code-server-config:
|
||||
Reference in new issue
Block a user