Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

They help only to the extent that you have completely isolated credentials: the hard part isn’t the container, it’s things like fastidiously using separate least-privilege credentials everywhere and not using tools or editor integrations which don’t support that style of work. Once you map your GitHub or AWS token into a container, it’s no longer useful as a security boundary.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: