i love selfhosting :3

Proxmox:  Debian Container 1: Pihole blocking more than 2.6M domains  Debian Container 2: Docker containers: traefik, Joplin Server and Homarr. Traefik connects to Cloudflare and mijndomein  Debian Container 3: Docker container: Jellyfin containing three folders for media  TrueNAS CE VM: Two Drives configured with RAID and Nextcloud (+Memories)
you are viewing a single comment's thread
view the rest of the comments
[–] 2 points 5 months ago

Soooo this is not really true unless you don't trust your kernel. While a VM is more isolated from the host, since a container shares kernel space, that doesn't make it less secure. I.E. isolation does not equal security.

Actual sandbox escape vulnerabilities happen in VMs as frequently as they do in Docker, and while all VMs have a full systems that many exfiltrations can hit (due to a full suite of services running), many docker containers are locked to a user space with only one process running.

@kureta@lemmy.ml if you are running separate Docker networks in compose, I would not recommend switching to VMs. If that kind of isolation is a requirement, add another server and use different SSH keys for it.

  • source
  • parent