A container is isolation, not a tiny virtual machine
The mental model of a small computer is wrong in a way that matters.
There is one kernel. A flaw in it, or a misconfiguration that relaxes the separation, affects everything on the host. Virtual machines fail differently because the boundary is enforced lower down. Both are legitimate; treating them as equivalent leads to running untrusted code in the wrong one.
More on Kubernetes
- Kubernetes RBAC controls API actions, not what a running container can then doChecked at the hatch, not inside the room
- A pod service account is an identityA badge on the same rail
- NetworkPolicy needs an enforcement engineHinges, but no gate
- Admission control can stop risky objects before they runStopped on the chute
- Privileged containers weaken the host boundaryThe floor is the boundary
- Mutable image tags can move underneath youSame ticket, different coat
