Docker Socket Proxies - enhanced security or just another attack vector? (Arcane + e.g. wollomatic)

Hi all, I'm a little bit confused about Docker Socket Proxies, and if they really improve security. I want to switch from Portainer to Arcane. In their documentation they recommend to use a socket proxy (wollomatic) to "Enhanced Security Setup A Docker socket proxy adds an extra layer of safety by letting Arcane use only the Docker features it actually needs.". But is it really an extra layer of safety? Arcane has +7,4k git stars and >80 contributors. wollomatic much smaller. In the end, I just introduce another 3rd party I need to trust and hope for no supply chain attacks to occure, while a docker management service like Arcane/Portainer/Dockhand etc. already needs most of the docker socket permissions ... So why is using Socket Proxies recommended here? And which have a high reputation?

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论