this post was submitted on 03 Feb 2024
405 points (95.3% liked)

linuxmemes

21173 readers
151 users here now

Hint: :q!


Sister communities:


Community rules (click to expand)

1. Follow the site-wide rules

2. Be civil
  • Understand the difference between a joke and an insult.
  • Do not harrass or attack members of the community for any reason.
  • Leave remarks of "peasantry" to the PCMR community. If you dislike an OS/service/application, attack the thing you dislike, not the individuals who use it. Some people may not have a choice.
  • Bigotry will not be tolerated.
  • These rules are somewhat loosened when the subject is a public figure. Still, do not attack their person or incite harrassment.
  • 3. Post Linux-related content
  • Including Unix and BSD.
  • Non-Linux content is acceptable as long as it makes a reference to Linux. For example, the poorly made mockery of sudo in Windows.
  • No porn. Even if you watch it on a Linux machine.
  • 4. No recent reposts
  • Everybody uses Arch btw, can't quit Vim, and wants to interject for a moment. You can stop now.

  • Please report posts and comments that break these rules!

    founded 1 year ago
    MODERATORS
     

    Next evolution, just a one line bash script.

    you are viewing a single comment's thread
    view the rest of the comments
    [–] JasonDJ@lemmy.zip -1 points 9 months ago (1 children)

    If it’s an open-source project, usually the dockerfiles are available for reading.

    Do you audit every line of code that you run in production? If you are trying some new python/django/sql app, are you reviewing all that?

    I’d assume with a python based project, you’d be able to at least look at requirements and tell there’s something that sets off red flags. And you are either familiar/trust the maintainer, or you are reviewing the actual python itself?

    Beyond that, the dockerfile is essentially just installation instructions for getting it running on a virgin system of X distribution. I wouldn’t call that a black box.

    If the container isn’t part of an open source project, then this is a moot point then. The project itself is a black box.

    [–] zaphod@lemmy.ca 1 points 9 months ago* (last edited 9 months ago) (1 children)

    You do you. Speaking for myself, I prefer to understand and be able to trivially inspect and modify the moving parts in the things I deploy so I have a snowball's chance in hell of debugging and fixing things when something inevitably goes wrong.

    [–] JasonDJ@lemmy.zip -2 points 9 months ago (1 children)
    [–] zaphod@lemmy.ca 1 points 9 months ago (1 children)

    And all I see is someone taking this conversation way too personally.

    [–] JasonDJ@lemmy.zip -2 points 9 months ago

    You sound like someone who doesn’t want to save 10 minutes of work every day because it might cost you half an hour every month.