Comment by danlitt 2 months ago Same reason people give postgres, php, or any other program a user account. 3 comments danlitt Reply dcow 2 months ago Why should it be? We have containers and capabilities… thwarted 2 months ago Containers are often used with user namespaces, which is literally another (set of) user account(s). khalic 2 months ago Yes but the encompassing service has the account, not the agent. You can completely segregate it from the rest of the system, like you’d treat an intruder
dcow 2 months ago Why should it be? We have containers and capabilities… thwarted 2 months ago Containers are often used with user namespaces, which is literally another (set of) user account(s). khalic 2 months ago Yes but the encompassing service has the account, not the agent. You can completely segregate it from the rest of the system, like you’d treat an intruder
thwarted 2 months ago Containers are often used with user namespaces, which is literally another (set of) user account(s). khalic 2 months ago Yes but the encompassing service has the account, not the agent. You can completely segregate it from the rest of the system, like you’d treat an intruder
khalic 2 months ago Yes but the encompassing service has the account, not the agent. You can completely segregate it from the rest of the system, like you’d treat an intruder
Why should it be? We have containers and capabilities…
Containers are often used with user namespaces, which is literally another (set of) user account(s).
Yes but the encompassing service has the account, not the agent. You can completely segregate it from the rest of the system, like you’d treat an intruder