glizzyguzzler

joined 2 years ago
[–] [email protected] 4 points 1 week ago* (last edited 1 week ago)
[–] [email protected] 9 points 1 week ago

Nice OC very relatable 11/10

[–] [email protected] 5 points 1 week ago

Carol want what carol want

[–] [email protected] 14 points 3 weeks ago

Hell yeah bröther

[–] [email protected] 3 points 1 month ago

I wish too for an in-depth blog post, but the github answer is at least succinct enough

[–] [email protected] 7 points 1 month ago* (last edited 1 month ago) (2 children)

This answers all of your questions: https://github.com/containers/podman/discussions/13728 (link was edited, accidentally linked a redhat blog post that didn’t answer your Q directly but does make clear that specifying a user in rootless podman is important for security for the user running the rootless podman container if that user does more than just run the rootless podman container).

So the best defense plus ease of use is podman root assigning non-root UIDs to the containers. You can do the same with Docker, but Docker with non-root UIDs assigned still caries the risk of the root-level Docker daemon being hacked and exploited. Podman does not have a daemon to be hacked and exploited, meaning root Podman with non-root UIDs assigned has no downsides!

[–] [email protected] 9 points 1 month ago

I would trust my life to this genius math dog’s calculations

[–] [email protected] 3 points 1 month ago

Look, I’m not perverted, I’m just Italian

 
[–] [email protected] 15 points 1 month ago

This is shit, I looked at the EU limits on cadmium/lead per the lab reports https://gmoscience.org/wp-content/uploads/2025/01/GSC-HeavyMetalsReports.pdf and EU limits https://eur-lex.europa.eu/legal-content/en/TXT/?uri=CELEX%3A32023R0915 (mg/kg == ppm, ug/kg == ppb) and their heavy metal amounts are very low.

For the aluminum the EU recommends 1 mg/kg per week on avg - but this EU report makes clear that ~10 mg/kg in baked goods is the norm https://efsa.onlinelibrary.wiley.com/doi/epdf/10.2903/j.efsa.2008.754 . So that’s even fine.

I don’t care to go into the pesticides but since the metal levels are good to fine but presented as horrendous, I would suspect the pesticide levels are overinflated as well.

 
110
rule (files.catbox.moe)
 
[–] [email protected] 4 points 1 month ago

I don’t have many books and yet you have quite a few of them as well, clearly you have exquisite taste

[–] [email protected] 1 points 1 month ago (1 children)

I see, do you know of a way in Docker (or Podman) to bind to a specific network interface on the host? (So that a container could use a macvlan adapter on the host)

Or are you more advocating for putting the Docker/Podman containers inside of a VM/LXC that has the macvlan adapter (or fancy incus bridge adapter) attached?

[–] [email protected] 3 points 1 month ago (3 children)

Confused at this sentiment, Docker includes a MACVLAN driver so clearly it’s intended to be used. Do you eschew any networking in Docker beyond the default bridge for some reason?

 

I have a bridge device set up with systemd, br0, that replaces my primary ethernet eth0. With the br0 bridge device, Incus is able to create containers/VMs that have unique MAC addresses that are then assigned IP addresses by my DHCP server. (sudo incus profile device add <profileName> eth0 nic nictype=bridged parent=br0) Additionally, the containers/VMs can directly contact the host, unlike with MACVLAN.

With Docker, I can't see a way to get the same feature-set with their options. I have MACVLAN working, but it is even shoddier than the Incus implementation as it can't do DHCP without a poorly-maintained plugin. And the host cannot contact the container due to the MACVLAN method (precludes running a container like a DNS server that the host server would want to rely on).

Is there a way I've missed with the bridge driver to specify a specific parent device? Can I make another bridge device off of br0 and bind to that one host-like? Searching really fell apart when I got to this point.

Also, if someone knows how to match Incus' networking capability with Podman, I would love to hear that. I'm eyeing trying to move to Podman Quadlets (with Debian 13) after I've got myself well-versed with Docker (and its vast support infrastructure to learn from).

Hoping someone has solved this and wants to share their powers. I can always put a Docker/podman inside of an Incus container, but I'd like to avoid onioning if possible.

65
butts rule (files.catbox.moe)
 
101
rule (files.catbox.moe)
353
tithe rule (files.catbox.moe)
 
162
praxis rule (files.catbox.moe)
 
361
rule (files.catbox.moe)
 
 
 

Context is:

  • I was luckily banned from the fallen onehundredninetysix for vehemently rejecting the orchestrated hoodwinking

  • luckily banned because i'd have posted boston's sloppiest there like three times before it properly made it to the people's onehundredninetysix

  • I use the default web UI which is aggressively broken on my old phone like the pleb I am

90
🤤🤤rule (files.catbox.moe)
 
view more: next ›