I understand that the docker daemon requires running as root , so I am told that this can lead to some security consequences, for example, if the container is compromised, attackers can make changes to the host system files.
What precautions can be taken to mitigate damage in the event of an attack?
Is there any practice I should know when starting the docker daemon? I was thinking that you have a tramp to start vm, and docker starts vm instead.
source share