Hacker News new | past | comments | ask | show | jobs | submit login

So you pass in the docker socket and the AIO container runs docker commands on the host?

That is correct, yes.

It sounds a bit like using the same password for all your services... Hack a Nextcloud instance, gain root on any system through Docker,

I would assume (hope) that the AIO container itself is not exposed to the internet, only some of the containers it starts.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact
