How to secure (podman or docker) containers for public-facing hosting?
Codilingus @ Codilingus @sh.itjust.works Posts 0Comments 493Joined 2 yr. ago
Codilingus @ Codilingus @sh.itjust.works
Posts
0
Comments
493
Joined
2 yr. ago
My solution that took awhile to figure out is fantastic IMO. Docker containers unprivileged, with nobody permissions, with their own IPs on macvlan, with matching vlan and good firewall rules. A docker network proxy container, Traefik, Authelia, CrowdSec, and a CrowdSec Traefik Bouncer containers.