you are viewing a single comment's thread
view the rest of the comments
[–] 3 points 4 hours ago* (1 child)

You definitely don't need containers to "run something that needs a different dependency", it's a massive waste of time and resources and just not what containers were made for. There are/were a thousand other solutions for this, from Nix to chroot to building from source to LD_LIBRARY_PATH to AppImage.

Containers were initially sold as a "security boundary" of sorts. The ability to run some software with the peace of mind that it won't ruin your OS or leak all your data if it's vulnerable. It's the entire point, but it turns out to be extremely difficult to get right. We managed to make a boundary against accidentally messing something up, not against targeted attacks.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 1 point 3 hours ago

    Yeah, but Nix and every other solution you mentioned has their own tradeoff and ease of use friction between developer and devops. Containers have good ergonomics for both that it reduces friction to achieve ci/cd

  • source
  • parent