Hacker News new | past | comments | ask | show | jobs | submit login

Container's root most certainly does map to host root unless you've enabled user namespaces (which is painful).

However, root in a container does have many privileges dropped and seccomp policies applied (assuming you haven't turned seccomp off via k8s).




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: