logoalt Hacker News

mystifyingpoiyesterday at 8:24 PM2 repliesview on HN

`useradd` doesn't restrict network access.


Replies

kaffekakayesterday at 8:30 PM

I have used a separate user, but lately I have been using rootless podman containers instead for this reason. But I know too little about container escapes. So I am thinking about a combination.

Would a podman container run by a separate user provide any benefit over the two by themselves?

eikenberrytoday at 12:28 AM

Without any credentials does network access matter?