Spent most of yesterday and today doing a write up on #podman rootless containers in light of the #copyfail exploit.
I use containers for all sorts of things, and I run most of my infrastructure on Podman using rootless containers. For a while I had been meaning to do a write up on how you can use features in Podman to practice defense in depth for containerized workloads.
Copy Fail proved to be a great example to use when talking about containers, user namespaces, Linux capabilities, and more! I did not find much information specific to containers so I decided to dust-up the blog with my own exploration.
https://garrido.io/notes/podman-rootless-containers-copy-fail/
