Post #2181661
2026-05-04 22:32 UTC
Spent most of yesterday and today doing a write up on #podman rootless containers in light of the #copyfail exploit.
I use containers for all sorts of things, and I run most of my infrastructure on Podman using rootless containers. For a while I had been meaning to do a write up on how you can use features in Podman to practice defense in depth for containerized workloads.
Copy Fail proved to be a great example to use when talking about containers, user namespaces, Linux capabilities, and more! I did not find much information specific to containers so I decided to dust-up the blog with my own exploration.
https://garrido.io/notes/podman-rootless-containers-copy-fail/
Replies (3)
-
@godber@az.social 2026-05-05 18:37
@ggpsv@social.coop oh I read that this morning, well done
-
@jwd630@mastodon.social 2026-05-06 20:16
@ggpsv@social.coop saw the article via the lobst.rs feed. Think I learned a lot as I am ramping up on podman. Thanks!
-
@emmecola@fediscience.org 2026-05-10 19:56
@ggpsv@social.coop Fantastic article, thanks! ๐๐ป