Ucieczka z kontenera Docker na Windowsie przy pomocy SSRF
Znacie to uczucie, gdy weryfikujecie założenia projektowe czy wdrożone polityki i coś się nie zgadza? Tego właśnie doznał użytkownik Dockera, który przez złe doświadczenia z wirtualizacją, postanowił sprawdzić izolację sieciową w kontenerach. TLDR: Badacz przez przypadek odkrył problem, pozwalający na przejęcie kontroli nad hostem, w sytuacji gdy wykorzystywany jest Docker...
#WBiegu #Docker #DockerDesktop #Escape #Podatność #Windows
https://sekurak.pl/ucieczka-z-kontenera-docker-na-windowsie-przy-pomocy-ssrf/
#GlobalSumudFlotilla https://mastodon.social/@la_voix/115133052454213773 : «Nous bloquerons toute l’ #Europe» : les dockers de Gênes feront grève pour protéger la flottille https://mastodon.social/@la_voix/115122960296623948 pour Gaza https://www.revolutionpermanente.fr/Nous-bloquerons-toute-l-Europe-les-dockers-de-Genes-feront-greve-pour-proteger-la-flottille-pour
De l'Indochine à #Gaza quand les #dockers se mobilisent contre la guerre https://www.slate.fr/monde/guerre-indochine-gaza-dockers-mobilisation-blocage-livraison-cargaisons-armement-israel-transport-maritime-desobeissance-syndicats

Because Docker just crashed on my working laptop (MacOS), has to reinstall Docker Desktop and this shows up.
Hmmm, Docker Subscription?
From a quick read from the Service Agreement, from what I understand is that if you use Docker, you are technically using a subscription of a limited Docker license that renews every 30 days.
Damn I wish I can move the podman but it didn't work well with company products
#docker #podman #container #macos

Don't you love that this happens after a I went back from taking a dump
#thisshitissoass #docker #macos #osx

[Blog] Running PostgreSQL with PgBouncer on Mac OS Using Docker Compose: https://www.sqlpassion.at/archive/2025/09/01/running-postgresql-with-pgbouncer-on-macos-using-docker-compose/ #postgres #PostgreSQL #pgbouncer #Docker
I had a strange idea. My setup became really terminal first and now I'm experimenting with something. Instead of having a Linux VM to work on a corporate Windows laptop, why not have a #DockerFile that describes my complete setup and if I need it at work, I fetch from my own repo, it starts a ssh server, I login and bam! I have my usual setup. There is a lot of good sides using #docker, it's more secure cause it gets destroyed every time I close my laptop, I have more control over what is installed, it expands as needed, the source code is shared between the host and the docker container so if something happen I'm safe. The only bad side is it sort of force a terminal only setup instead of terminal first as far as I know. I could actually run the UI in a browser if I want to.
Es war mal wieder Zeit für ein PiHole-Update.
Direkt vom docker-Image 2024.07.0 auf 2025.07.0
Habe auf meinem Spof-Server im homelab alle meine Container als Podman-Quadlets konfiguriert um sie ohne root-Privilegien und gut in Systemd integriert zu betreiben.
Eine Zahl in der .container-Datei unter ~/.config/containers/systemd ändern, dann mit
systemctl --user daemon-reload
die Quadlets neu erstellen lassen und mit
systemctl --user restart container-pihole.service
Das neue Image starten.
Fertig.
Mehr zur Podman-Systemd-Integration:
man quadlet
#homelab #docker #podman #selfhost #pihole #systemd

Vercel just discontinued Node 18 and left me unable to deploy some of my Nextjs websites. Since I am having a hard time updating them to Node 20 or later, I’m looking for Vercel alternatives that can work with older Node versions indefinitely.
I have a kubernetes cluster that I could use, but don’t know what would be the best approach.
#docker #kubernetes #vercel #nextjs
I noticed yesterday that #syncthing in my main server was scanning slowly the biggest folder with 200k+ files. I increased hash workers to 20 and it got four times faster. Today I noticed that the Syncthing #docker container had CPU pinnings with only two cores allowed. Now I'm a bit puzzled why it got so much faster with only 2+ threads (2 cores + 2 hyperthreads).
Some experimenting ahead. I can try less workers and more cores. I prefer to make the sync as fast as possible, since it is #kopia backup database. The destination copy is probably inconsistent until fully synced.
#homelab
Como ver contenido acestream en Linux https://myblog.clonbg.es/como-ver-contenido-acestream-en-linux/ #Docker #Media https://clonbg.es

Bon avec cet article je vois enfin comment faire pour ne plus jamais avoir à écrire http://localhost:687900 pour accéder à un conteneur quelconque, mais plutôt http://monservice.dockerhost.local. Il me manque juste un conteneur magique qui mette à jour mon fichier /etc/hosts quand un conteneur démarre, et ce sera parfait (oui, c'est un peu ridicule pour moi qui ait fait il y a des années une grosses mission… https://franfabrizio.dev/posts/setting-up-a-traefik-reverse-proxy-for-docker/ #docker #http #dns #redirector #tutorial
7 Quick Steps for Managing #Docker Containers on #Debian VPS Servers
This guide provides 7 quick steps for managing Docker containers on Debian VPS servers. It is designed for system administrators and developers who are familiar with basic Linux commands and concepts.
7 Quick Steps for Managing Docker Containers on Debian VPS Servers
Docker has revolutionized the software development industry by making it possible to package applications ...
Continued 👉 https://blog.radwebhosting.com/7-quick-steps-for-managing-docker-containers-on-debian-vps-servers/?utm_source=ReviveOldPost&utm_medium=social&utm_campaign=ReviveOldPost #vpsguide