dasgewisseextra@sh.itjust.workstoSelfhosted@lemmy.world•Podman or rootless docker?English
2·
3 months agoI switched from Dockerd to K3s. First you get the benefits of the Kubernetes API but also Pod Security Context, Pod Security Admission and Network Policies which help to reduce attack surface while simplifying your setup. But if you do want to use Podman look into running your containers as read only, drop all capabilities and unprivileged.
Nice but weird that Lutris and Heroic are classified as a game unlike Steam which correctly is a game launcher