1 |
On Thu, Jun 16, 2016 at 04:33:12PM -0400, Rich Freeman wrote |
2 |
> On Thu, Jun 16, 2016 at 4:11 PM, Alan McKinnon <alan.mckinnon@×××××.com> wrote: |
3 |
> > |
4 |
> > I don't see the part where all these latest fancy container thingymagicies |
5 |
> > are not really just "embed everything in everything" |
6 |
> > |
7 |
> > We've known for years the dangers of embedding stuff in packages (it hardly |
8 |
> > ever gets updated properly) |
9 |
> > |
10 |
> |
11 |
> Well, that strikes me as being true of these self-contained packages, |
12 |
> but it isn't necessarily true of containers in general. |
13 |
> |
14 |
> I run most of my services in containers, and they're just Gentoo |
15 |
> installations with a really small world file. Things are just as |
16 |
> up-to-date as they would be if I ran it all in a single host. |
17 |
> |
18 |
> Now, if you're the sort of person who just grabs some random docker |
19 |
> image from who knows where, then sure you're getting a big bundle of |
20 |
> stuff that may or may not be maintained for security. This is no |
21 |
> different. |
22 |
|
23 |
I don't follow this stuff, so this may be a stupid question... how |
24 |
does a "container" or "docker" differ from a chroot or a QEMU VM with a |
25 |
minimal set of applications? |
26 |
|
27 |
-- |
28 |
Walter Dnes <waltdnes@××××××××.org> |
29 |
I don't run "desktop environments"; I run useful applications |