song4's recent timeline updates
song4's repos on GitHub
Rust · 2555 watchers
charming
A visualization library for Rust
Python · 7 watchers
LmlParser
A minimal parser for AWS API Gateway responding data.
Ruby · 4 watchers
FunTalk
The Fun Talk App
HCL · 3 watchers
google-cloud-service-agents
Exposes a list of service agents for given Google project.
2 watchers
awesome-handbooks
A curated list of awesome employee handbooks.
Rust · 2 watchers
birdie
Birdie is a third party Binance API client, allowing you to easily interact with the Binance API using Rust.
HTML · 2 watchers
CocoaShelf
Cocoa shelf
1 watchers
awesome-everything-as-code
A curated list of awesome everything-as-code tools, frameworks, and approaches.
Rust · 1 watchers
magic-cli
Command line utility to make you a magician in the terminal
JavaScript · 0 watchers
admin-on-rest
A frontend framework for building admin SPAs on top of REST services, using React and Material Design
Python · 0 watchers
adventofcode
Python · 0 watchers
adventofcode-2019
Java · 0 watchers
algs4
Algorithms, 4th edition textbook code and libraries
0 watchers
anata-no-minato
0 watchers
ansible-nginx
An Ansible role that installs Nginx.
HTML · 0 watchers
archived-blog
Rust · 0 watchers
asterinas
Asterinas is a secure, fast, and general-purpose OS kernel, written in Rust and providing Linux-compatible ABI.
0 watchers
Auto_Wordlists
Makefile · 0 watchers
awesome-kubernetes
A curated list for awesome kubernetes sources :ship::tada:
Perl · 0 watchers
bandwidth-guard
Bandwidth Guard for Shadowsocks
0 watchers
banzai-charts
Curated list of Banzai Cloud Helm charts used by the Pipeline Platform
Python · 0 watchers
Baymax
Baymax - Personal Data Metrics
0 watchers
black-hat-rust
Applied offensive security with Rust - Early access - https://academy.kerkour.com/black-hat-rust?coupon=GITHUB
C · 0 watchers
blink
tiniest x86-64-linux emulator
HTML · 0 watchers
blog
C · 0 watchers
bloom-filter
Implementation of Bloom Filter.
0 watchers
bloop
bloop is a fast code search engine written in Rust.
0 watchers
book-extreme-c
Assembly · 0 watchers
boot-programming
C · 0 watchers
Cherry
Python · 0 watchers
climb
Python library for interactive command line applications.
C · 0 watchers
clisp
Go · 0 watchers
cloudwatch_exporter
A CloudWatch exporter for Prometheus coded in Go, with multi-region support
0 watchers
code
Source code for the book Rust in Action
C++ · 0 watchers
codevs.cn
Vim script · 0 watchers
config-files
Copies of my config files.
0 watchers
container-networking
Container networking from scratch, from a single namespace to an overlay network.
Rust · 0 watchers
coreutils
Cross-platform Rust rewrite of the GNU coreutils
Python · 0 watchers
cpython
The Python programming language
0 watchers
craftinginterpreters
Repository for the book "Crafting Interpreters"
C · 0 watchers
csv2mdtable
Convert CSV string to markdown table.
0 watchers
DCA
Docker Certified Associate Exam Preparation Guide
0 watchers
dca-prep-guide
Docker Certification Associate preparation guide - a list of resources to help you prepare for a successful certification
Python · 0 watchers
demo-repo
A demo repo.
Go · 0 watchers
devops-challenge
Three DevOps tasks.
0 watchers
DevopsWiki
A wiki of Devops Tools, Tutorials and Scripts
Shell · 0 watchers
docker-gitlab
Dockerized GitLab
JavaScript · 0 watchers
docker.github.io
Source repo for Docker's Documentation
0 watchers
documentation-website
The documentation for OpenSearch, OpenSearch Dashboards, and their associated plugins.
0 watchers
dotfiles-1
There is no place like ~/
0 watchers
egui
egui: an easy-to-use immediate mode GUI in Rust that runs on both web and native
C++ · 0 watchers
electron
Build cross platform desktop apps with JavaScript, HTML, and CSS
Go · 0 watchers
exercise-golang
0 watchers
fd
A simple, fast and user-friendly alternative to 'find'
0 watchers
fish-shell
The user-friendly command line shell.
Rust · 0 watchers
fist
Python · 0 watchers
flask
A microframework based on Werkzeug, Jinja2 and good intentions
Python · 0 watchers
Flask-Boot
Create new Flask apps.
JavaScript · 0 watchers
FunDevBlog
Blog for the FunPlus dis team.
0 watchers
gauntlet
Raycast-inspired open-source application launcher with React-based plugins
Shell · 0 watchers
gb
C · 0 watchers
ghidra
Rust · 0 watchers
gimage
JavaScript · 0 watchers
git-hooks
Swift · 0 watchers
GithubStar
The missing Github star manager.
0 watchers
gitignore
A collection of useful .gitignore templates
JavaScript · 0 watchers
gitlab-treeview
Go · 0 watchers
go-echarts
🎨 The adorable charts library for Golang
Go · 0 watchers
go-gin-prometheus
Gin Web Framework Prometheus metrics exporter
0 watchers
go-perfbook
Thoughts on Go performance optimization
Go · 0 watchers
go-sudoku
Python · 0 watchers
gocode-subl3
Sublime Text 3 plugin for gocode
Go · 0 watchers
goweight
A tool to analyze and troubleshoot a Go binary size.
Shell · 0 watchers
grafana-dashboards
List of Grafana Dashboards 📺
C · 0 watchers
Grid
Mac window manager.
0 watchers
Hacking-Security-Ebooks
Top 100 Hacking & Security E-Books (Free Download) - Powered by Yeahhub.com
Rust · 0 watchers
heh
A terminal UI to edit bytes by the nibble.
0 watchers
helpdesk-bot
Swift · 0 watchers
higgs-swift
Higgs - the swift data tracker
Go · 0 watchers
illustrated-tls
The Illustrated TLS Connection: Every byte explained
C++ · 0 watchers
ImageFreak
0 watchers
interactive-tutorials
Interactive Tutorials
0 watchers
interview
Everything you need to prepare for your technical interview
JavaScript · 0 watchers
js-sudoku
0 watchers
jsonvisio.com
🧩 Visualize your JSON data onto graphs seamlessly.
C · 0 watchers
keepalived
Keepalived
Jsonnet · 0 watchers
kf-test
Go · 0 watchers
komiser
AWS Environment Inspector 👮
Go · 0 watchers
kops
Kubernetes Operations (kops) - Production Grade K8s Installation, Upgrades, and Management
0 watchers
krew
📦 Find and install kubectl plugins
0 watchers
krew-index
Plugin index for https://github.com/kubernetes-sigs/krew. This repo is for plugin maintainers.
0 watchers
kubernetes-networking-links
Kubernetes Networking recommended reading list
Go · 0 watchers
kubewatch
Watch k8s events and trigger Handlers
0 watchers
lfs-me
Linux From Scratch made ( more ) easy. A simple, fakeroot based, package manager for LFS heavily inspired by Archlinux' package management.
0 watchers
linux
Linux kernel source tree
0 watchers
linux-hardening-checklist
Simple checklist to help you deploying the most important areas of the GNU/Linux production systems - work in progress.
0 watchers
linux-re-101
A collection of resources for linux reverse engineering
0 watchers
loco
🚂 🦀 The one-person framework for Rust for side-projects and startups
0 watchers
Lua-Source-Internal
Lua source internal
song4

song4

我想到了一个绝妙的签名,可惜这里太小,写不下。
V2EX member #57436, joined on 2014-03-05 13:05:50 +08:00
物理系出身,却干上了程序员的行当。

染指C++、Node.js、Python和Java。

喜好数学、物理、逻辑和哲学。

对于有同样爱好的童鞋,我只有一句话:请联系我。
song4's recent replies
支持一下,想来新加坡的朋友们可以考虑一下。这枚 HR 超赞的。
先回答第一个问题:

> 如果 docker 中的用户名交 dockeruser 宿主机没有这个用户,他是怎么映射的呢?按照 uid 吗?

是的,按照 uid 来映射。默认从 uid=0 开始映射,宿主机的 uid=0,1,2,... 映射为容器的 uid=0,1,2,...。你可以通过 `--userns-remap` 选项来改变这个行为,比如说可以指定宿主机的 uid=1000,1001,1002,... 映射为容器的 uid=0,1,2,...。

第二个问题:

> 所以在容器内就是 root 权限了,怎么避免呢?

事实确实是这样的,你可以参考 LWN 的这篇文章:[User namespaces + overlayfs = root privileges]( https://lwn.net/Articles/671641/)。这一点其实在 Docker 官方给出的 [Docker daemon attack surface]( https://docs.docker.com/engine/security/security/) 中也已经指出来了:

> Docker allows you to share a directory between the Docker host and a guest container; and it allows you to do so without limiting the access rights of the container. This means that you can start a container where the /host directory is the / directory on your host; and the container can alter your host filesystem without any restriction. This is similar to how virtualization systems allow filesystem resource sharing. Nothing prevents you from sharing your root filesystem (or even your root block device) with a virtual machine.

那么,怎么避免呢?一种方案是,可以在运行容器的时候通过 `--user` 选项指定非 root 用户名和组。另外,挂载 volumes 的时候遵循 Principle of Least Privilege 是一个好习惯:尽量避免挂载系统重要的目录或文件,如果实在需要,不妨使用只读挂载。
@monsterxx03 是对的,做 Capacity Planning 的话,还需要知道应用的工作负载特征。
@abmin521 是的
我是 DevOps 工程师
@tyrealgray 这个应该好协调的吧,不清楚您当时的具体情况 😂
@mygoare 我们业务中用到的是 React,如果你学习能力足够强,欢迎投递简历!
@jishu541464750 你够了。。。
Dec 12, 2018
Replied to a topic by summersnow521 Java Java DevOps 最贱实践讨论
你是想讨论“最贱实践”还是“最佳实践”?
About   ·   Help   ·   Advertise   ·   Blog   ·   API   ·   FAQ   ·   Solana   ·   920 Online   Highest 6679   ·     Select Language
创意工作者们的社区
World is powered by solitude
VERSION: 3.9.8.5 · 32ms · UTC 20:30 · PVG 04:30 · LAX 13:30 · JFK 16:30
♥ Do have faith in what you're doing.