-
-
Notifications
You must be signed in to change notification settings - Fork 2.5k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
App in Docker: not completely isolated? #24
Comments
There is work being done to secure X11 by some gnome people I believe but On Fri, Jun 5, 2015 at 4:22 PM, TerrorFactor notifications@github.com
Jessie Frazelle |
Would using VNC work? I'd guess I have to make an image with a VNC server in it, which will give some overhead, but if it's really isolated that way, that's okay. It'll still be better than running a VM for every app. |
I honestly don't think so, but would be interesting to try. On Fri, Jun 5, 2015 at 4:30 PM, TerrorFactor notifications@github.com
Jessie Frazelle |
Sooooo, it seems that I can't even get your stock image to build: The command .... returned a non-zero code: 100 Updating your image without rebuilding also doesn't seem to be an option, as I can't get a shell due to the X11 requirement. |
Hmm thats odd seeing as I just updated all of them and they built just On Fri, Jun 5, 2015 at 6:10 PM, TerrorFactor notifications@github.com
Jessie Frazelle |
That's weird. I'm using a pretty much fresh installed 14.04 64 bit ubuntu, and only installed docker today. I'll install a fresh VM and have another go. There isn't anything special needed to build an image as far as I know? |
It did work on a fresh VM with a fresh docker. Added another repository, guessing i'm having a different version of docker now. |
You can use subuser's secure X11 bridge to provide X11 isolation. I am currently working on getting @jfrazelle's repository ported to subuser. Stay tuned. |
@timthelion results on the porting? |
closing as this is not bugs with this repo, thanks! but feel free to discuss! |
When messing around with your Docker images, I wanted to check if a container was completely isolated. I tried it with your Spotify image, as I know Spotify doesn't like being started multiple times.
So I created 2 containers with your Spotify-image, and tried to run them both.
It didn't work :(
Spotify knew there was already a Spotify running. I figured it might be, because both instances were mapped to the same folders on the host, so I changed that. No luck.
Upon googling a bit more, I suspect it's because X11 is used. Do you know how to fix that, or is there a workaround?
The text was updated successfully, but these errors were encountered: