Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)N
Posts
1
Comments
23
Joined
3 yr. ago

  • A VLAN is (theoretically) equivalent to a physically separated layer 2 domain. The only way for machines to communicate between vlans is via a gateway interface.

    If you don't trust the operating system, then you don't trust that it won't change it's IP/subnet to just hop onto the other network. Or even send packets with the other network's header and spoof packets onto the other subnets.

    It's trivially easy to malform broadcast traffic and hop subnets, or to use various arp table attacks to trick the switching device. If you need to segregate traffic, you need a VLAN.

    Edit: Should probably note that simply VLAN tagging from the endpoints on a trunk port isn't any better than subnetting, since an untrusted machine can just tag packets however it wants. You need to use an 802.1q aware switch and gateway to use VLANs effectively.

  • What you are asking will work. That's the whole point of subnets. No you don't need a VLAN to segregate traffic. It can be helpful for things like broadcast control.

    However, you used the word "trust" which means that this is a security concern. If you are subnetting because of trust, then yes you absolutely do need to use VLANs.

  • Just cause you've never seen them doesn't make it not true.

    Try using quadlet and a .container file on current Debian stable. It doesn't work. Architecture changed, quadlet is now recommended.

    Try setting device permissions in the container after updating to Debian testing. Also doesn't work the same way. Architecture changed.

    Redhat hasn't ruined it yet, but Ansible should provide a pretty good idea of the potential trajectory.

  • It isn't. It's architecture changes pretty significantly with each version, which is annoying when you need it to be stable. It's also dominated by Redhat, which is a legit concern since they'll likely start paywalling capabilities eventually.

  • Every complaint here is PEBKAC.

    It's a legit argument that Docker has a stable architecture while podman is still evolving, but that's how software do. I haven't seen anything that isn't backward compatible, or very strongly deprecated with notice.

    Complaining about selinux in 2024? Setenforce 0, audit2allow, and get on with it.

    Docker doing that while selinux is enforcing is an actual bad thing that you don't want.

  • Instead of paying for multiple services, I am now renting a decently sized VPS on Scaleway, and hosting all my projects on them.

    That's not self hosting. That's moving your managed services down the stack from PaaS to IsaS.

    It's an unserious take on the impacts as well. No discussion of availability? Backups? Server hardening and general security? Access and authentication models? Sysadmin on aVPS is more than "running a bunch of commands now and then", and the author ignores that entire workload.