Skip to main content



Exposing docker socket to a container


Do you guys expose the docker socket to any of your containers or is that a strict no-no? What are your thoughts behind it if you don't? How do you justify this decision from a security standpoint if you do?

I am still fairly new to docker but I like the idea of something like Watchtower. Even though I am not a fan of auto-updates and I probably wouldn't use that feature I still find it interesting to get a notification if some container needs an update. However, it needs to have access to the docker socket to do its work and I read a lot about that and that this is a bad idea which can result in root access on your host filesystem from within a container.

There are probably other containers as well especially in this whole monitoring and maintenance category, that need that privilege, so I wanted to ask how other people handle this situation.

Cheers!

in reply to 5ymm3trY

@selfhosted I found #regctl github.com/regclient/regclient Using it a made a script to check and compare the sha1 of any image locally with the remote ones, then act accordingly
docker images --digests foo/foo <a class="hashtag" data-tag="for" href="https://fe.disroot.org/tag/for" rel="tag ugc">#[url=https://fe.disroot.org/tags/for]for[/url]</a> the locally one  
regctl manifest head foo/foot <a class="hashtag" data-tag="for" href="https://fe.disroot.org/tag/for" rel="tag ugc">#[url=https://fe.disroot.org/tags/for]for[/url]</a> the remote one
in reply to 5ymm3trY

I use Podman with Diun (like Watchtower but no auto-updates) and I think that's the only time I've had to mount the socket into the container. Maybe also CrowdSec. Podman is rootless so I feel a bit better about it.


Man fleeing Home Depot immigration raid is struck, killed by car on the 210 Freeway


A man was hit and killed on the 210 Freeway on Thursday as he tried to flee federal agents raiding a Home Depot in Monrovia, CA.
in reply to undefined

It's interesting because the person was looking for work, I thought ICE said they were going after criminals?


Happy birthday Jim Wynorski


Former Roger Corman protege, and director of over 100 films, including classics like Chopping Mall, Deathstalker II, and non-classics like Murderbot (no, not that one) and Attack of the 50 Foot CamGirl.
This entry was edited (1 day ago)




Premier Doug Ford's government is ordering Ontario public servants to work from the office four days a week starting this fall and then full-time in January


cross-posted from: lemmy.ml/post/34679997

Dude was getting lonely not being able to micromanage the lives of government employees.



Premier Doug Ford's government is ordering Ontario public servants to work from the office four days a week starting this fall and then full-time in January


Dude was getting lonely not being able to micromanage the lives of government employees.




wplace rule


::: spoiler Transcript
A fediverse post by sodiboo @sodiboo@gaysex.cloud.
It says "back in my day we didn't need wplace we just went outside and vandalized the real deal"
The post was made 1 day ago.
:::



Agenda Prep for August 2025 ForumWG Meeting


[url=https://docs.google.com/document/d/1r64A6bvDo1B0eQ3vdwDZtCwu-s4G1xWnaHVZB1gg9N8/edit?usp=sharing]Agenda preparation for the April ForumWG meeting can be found at this public link[/url] (anyone can make comments for review.) Monthly meetings are held

Agenda preparation for the April ForumWG meeting can be found at this public link (anyone can make comments for review.)

Monthly meetings are held on the first Thursday of each month, at 13h00 to 14h00 Eastern Time (currently 17h00 to 18h00 UTC). You can find them listed in the SocialCG Calendar. The next meeting will be held on 7 August 2025.

We will be discussing:

  • FEP 7888/f228 adoption update
  • Context Inheritance
  • Context Ownership
  • Merging of Contexts (aka "cross-posting")



Stubsack: weekly thread for sneers not worth an entire post, week ending 17th August 2025


in reply to cy

in reply to Wulfy

Worst thing about neo luddites is the Luddites weren't opposed to technology. They just didn't like how one guy got to own the whole factory. So I get why people don't want to risk learning about some stupid stuff, but they're not luddites.


Zine Stitching Identity


Stitching Identity: Flags, Pride and Memory Every June 28, the LGBTIQANB+ community mobilizes around the world to raise awareness about the struggle against hate crimes. For me, more than a celebration, this date has always been a reminder that without
This entry was edited (2 days ago)


in reply to Sunshine

Academic here. I'm arguing amongst my colleagues that, practically, its already a hybrid regime. What's that? Think China or Iran. Some local autonomy, some voting, but the real power is centralized in one person or party. A touch of aged democracy with a heavy dose of authoritarianism baked at 451 degrees.

The Constitution is not worthless, not bynany means. Its useful but in a new way. It has been co-opted into the regimes (and it is a regime now) ruling apparatus. A nostalgic and nebulous rallying cry when needed, and a useless piece of paper that doesn't apply when necessary. Because the rule of law, that all important and oft misunderstood phrase, is truly dead, the regime can and is doing whatever it wants.

There may be a few moments of respite, a court case win a back off there, but those are strategic withdrawals. Distract and redirect.

That's all. Keep your heads up, fight for a better tomorrow even if today is lost.





US alcohol consumption at a record low as health warnings grow, survey finds


Alcohol consumption among adults in the US is at the lowest level on record, as most Americans, for the first time, view even moderate drinking as harmful, a new survey has found.

Pollster Gallup’s latest Consumption Habits survey, conducted annually, showed that about 54% of Americans reported drinking alcohol, compared with 58% in 2024 and 62% in 2023.

The figure falls below the previous record low of 55% in 1958 in the nearly nine decades of such tracking by Gallup. And the figure appears not to be driven by people turning to alternatives, such as legal recreational cannabis, the researchers said.


So, by supply and demand, why aren't beer prices going down?

in reply to Powderhorn

Went to a family event the other day. We realized it was the first one we were having without Boomers. By coincidence(?) it was also the first one we had which was completely alcohol free. Everyone just happened to bring no alcohol.


Karate or Tae Kwon Do for kids?


Hi everyone! So, my niece is alsmost 6 years old and is very energetic and generaly active as a child. Her parents are thinking of sending her to either Karate or Tae Kwon Do, both for physical and spiritual exercise and development.
Which one do you think could fit better for her age and also considering she likes it which is better in the long term?
in reply to WeAreAllOne

Taekwondo is a core Olympic sport while Karate has only appeared once, so there's the motivational factor of seeing top level competition being televised.



in reply to J

Gotta love the clickbait headlines! I read the article and watched the video linked within, and neither one clarifies WHICH version of the Hulk we'll see in Spider-Man!
in reply to Agrivar

Welcome to the internet, it never gives a straight answer


Alberta’s Perverse New Barriers to COVID Vaccines | The Tyee


I made the biggest political donation of my life after this policy was announced - and sent a screenshot to my (barely elected) UCP MLA letting him know. There's a lot to hate the UCP for, but this one really takes the cake.


What Does Palantir Actually Do?


https://www.wired.com/story/palantir-what-the-company-does/


in reply to PhilipTheBucket

🎶America, fuck yeah! 🎶

There's nothing we can't profit off of!



„We Are Lady Parts“ (Serie, 2021-2024)

Ich liebe sie alle. Keine weniger als die andere. Für das, was sie sind und für das, was sie tun! Hier hat das @ZDF einmal mehr in den britischen Serienkatalog gegriffen und viel mehr als eine Serienperle an Land gezogen. Das hier ist ein gesellschaftspolitisches Statement, das im Gewand einer Punkband-Sitcom zugleich emanzipatorisch und subversiv agiert. Gut so! (ZDF, Neu!)



Are distros really different or is it more about preference?


in reply to Jack_Burton

Distros within the same "family" (e.g. Debian, Ubuntu, Mint) are mostly the same with only small differences between them, while the different families have wildly different approaches to various things.


A Republican's sex scandal exposes the media's evolving shrug toward congressional disgrace





in reply to lazynooblet

I contributed to this, but I always thought that the Western obsession with moving out at 18 was really weird and wasteful. Obviously everyone is different, but when I've talked to non Western residents who do family housing, one saves money on rent, food, housework, etc. Old people are cared for and have something to do, parents get help with baby sitting, kids haves more adult interactions.

That said, I've talked to enough non Western residents who this setting failed for them because their family was toxic. I'm sure that happens too.

I don't pretend to know about this very well, so please forgive me if this sounds like an authoritative word.

in reply to ButtBidet [he/him]

Spanish here. We move late* (traditionally when married somewhen in the twenties) and remain close to our families. We like it.

But that used to be a choice. You could move out sooner if you liked (in previous generations, only men,obviously).

The problem is when you can't even plan moving out before you are forty. Even if your family is not toxic, there's a very low chance of building your own life.

* From my perspective it is not late, it is just the right time.

This entry was edited (3 days ago)

in reply to rauls5

@johnefrancis pretty weak… and they even manage to be oblivious that they spelled both "favourite" and "flavour" the non-Canadian way, just to drive home the pathetic attempt at #mapleWashing



Public School Enrollment Is Declining — But Not Everywhere, or for All Students




Open Lemmy comment threads in Mastodon?


Since both lemmy and Mastodon use the fediverse, is it possible to view comment threads under posts from lemmy in Mastodon? How to find a link that works in both/ is it related to the posts id?

Would these work with #hashtags ?

This entry was edited (3 days ago)
in reply to scratsearcher 🔍🔮📊🎲

@AWUutgQ5inc7fMWpTk.fediverse@lemmy.ml hello, in my experience it is possible and yes, hashtags works. Right know I’m seeing your post and giving an answer from #Akkoma thanks to your hashtag.

In order to find a post (without the # ) you have to follow the community or account you are interest. Links work fine when you share it on Mastodon for example. The only difficult is to find a community because you don’t have the search options that you have in #Lemmy and makes it more easy. But hashtags are great to solve that barrier.


in reply to cyborganism

I spent about a decade as a KDE developer.

KDE has this mindset where if someone wants to implement something they think is cool, and the code is clean and mostly bug free, well -- have at it! Ever wonder why there's 300 options for everything?

Usually (because there's a bunch of people trying to optimize the core for speed and load times and such) this also means that the unused code-paths are required to not contribute negatively to things like load times. So a plugin like this that doesn't get loaded by default unless enabled, and thus doesn't harm everyone else's performance. It also means that if it stops working in the future and starts to bitrot, it can be dropped without affecting the core code.

in reply to schnurrito

In my entire life (and as context my earliest experiences with a PC predate the first consumer-available apple computer) there has not been a single time where I have felt the phrase "only Apple can achieve" to be worthy of anything other than a snort.

Apple's unshakable confidence that everything they do is earth shattering is overlapping heavily with that mediocre white man saying these days.

This entry was edited (3 days ago)


Leaked list shows Facebook training their AI on multiple Lemmy instances


Filtered word: nsfw

This entry was edited (1 week ago)


Suspect arrested after shooting at Texas Target kills at least three people


A gunman opened fire outside a Target store in Austin, Texas, on Monday, killing at least three people and injuring a fourth. The suspect, who fled the scene in a stolen car, is in police custody according to local officials.

The name of the shooter has not been released, but was identified as a white 32-year-old man with a history of mental health issues, said the Austin police chief, Lisa Davis.

An investigation into what unfolded in the Target parking lot and what may have contributed to this act of violence is still underway. Mental illness by itself is not a predictor of violence and only 5% shooting deaths in the US are committed by people with mental health disabilities, according to research from Columbia University’s Department of Psychiatry.


This occurred less than two miles from me, and everyone on the Austin subreddit is clamoring for a motive.

in reply to Powderhorn

youtube.com/watch?v=VYOjWnS4cM…