cross-posted from: https://lemmy.nz/post/37348943

you are viewing a single comment's thread
view the rest of the comments
[โ€“] 1 point 4 months ago (3 children)

It's so easy, why bother? But I have each service in a separate small Debian VM to avoid conflicts. This avoids conflicts, enforces limits, and gives kernel separation. The real kernel isn't running anything public.

  • source
  • parent
  • hideshow 3 child comments
  • [โ€“] 1 point 4 months ago (2 children)

    Because of all the other reasons containers are great. Mainly, avoiding maintaining a fleet of VMs...

  • source
  • parent
  • hideshow 2 child comments
  • [โ€“] 1 point 4 months ago (1 child)

    Containers are often used as a way to not have to keep things up to date, or install properly. Don't have to be, but often are. Also, not have a separate kernel means you aren't protected from things like the recent exploits when you allow things uploaded to run. Maintaining Debian Stable is easy really. Love me some Debian. ๐Ÿ˜€

  • source
  • parent
  • hideshow 1 child comment