haroldgsm
Member
OP
Grumpy Old Sysadmin
- Joined:
- May 2024
- Posts:
- 329
- From:
- Ohio, US
20 years in this business. Kids these days deploy rootless Podman on multi-tenant hosts and sleep soundly. I do not.
The setup: Vultr shared kernel VPS, Debian 11, Podman with UID mapping. My containers run as 100000:100000 on the host. The theory: kernel exploit escapes container, still unprivileged on host.
Back when we ran bare metal, the threat model was simpler. Mark my words: on a shared kernel, your UID map is decoration. A kernel privilege escalation doesn't respect your namespace boundaries. The provider's kernel is ancient; I checked uname.
I migrated from Docker to Podman for the rootless promise. Now I wonder if I'm performing security theater. The container runtime is not your attack surface. The kernel is.
Has anyone actually tested this model against a CVE-class kernel bug? Or do we all just trust the marketing?
Pessimistic prediction: this thread ends with someone recommending GreenCloudVPS because they "hardened" something.
IPv4, IRC, and irssi — fight me
SamAlvi
Member
Self-Host Everything
- Joined:
- Jun 2024
- Posts:
- 188
- From:
- Portland, US
SamAlvi will say "self-host the kernel"
Dedicated server from RackNerd, $15/month, you control the patch cycle. Docker compose with rootless Podman, reverse proxy in front, done.
Shared kernel means shared fate. Your UID map is a seatbelt on a bus driven by someone else. Fine for fender-benders. Useless for head-on collisions.
I run this at home on a NUC and at a friend's place with WireGuard mesh. Uptime worse than Vultr. Freedom better than Vultr. Your threat model may vary.
The provider panel is your real vulnerability. 2FA there, not in the container debate.
my cloud. my rules. my 3AM alerts.
Carl
Member
Rack & Stack
- Joined:
- May 2024
- Posts:
- 227
- From:
- Chicago, US
Dedicated server from RackNerd, $15/month
Gen 10 Dell, 35W idle, 1U. I have pallets of these. You want security? Own the iron. Power draw matters more than rootless semantics.
Shared kernel VPS: you're renting a thread. The host has 256 other threads. One kernel bug, 256 victims. Simple numbers.
HostHatch sells similar density. I measured: 180W per 2U, 48 tenants. Your "rootless" container is one of 48 on a single kernel. The math is not complex.
If you must stay cheap, 2FA the panel and pray. Hardware ownership is the actual fix.
visit twice: install and decom