Live data from Hacker News

Omarchy: Any User Process Can Escalate to Root

0xcc.io

1–10 of 583 posts

Re: Omarchy: Any User Process Can Escalate to Root

#6
post #4

Why not use rootless podman? It is 2026 not 2016, Podman works much better than Docker today.

that's what I do and what the author recommends as well

Somehow I doubt DHH and company would be OK sacrificing ""developer experience"" for security... There is still a non-trivial amount of docker-compose files and Docker incantations that don't work 1:1 with podman and podman-compose. Adjusting them would require Omarchy's users underatanding podman, and I doubt this will align with the opinionated nature of Omarchy..

Re: Omarchy: Any User Process Can Escalate to Root

#7
post #4

Earlier quoted context omitted.

that's what I do and what the author recommends as well

Somehow I doubt DHH and company would be OK sacrificing ""developer experience"" for security... There is still a non-trivial amount of docker-compose files and Docker incantations that don't work 1:1 with podman and podman-compose. Adjusting them would require Omarchy's users underatanding podman, and I doubt this will align with the opinionated nature of Omarchy..

Come on. I am sure you don’t like DHH. But he’s always taken security seriously in Rails.

Re: Omarchy: Any User Process Can Escalate to Root

#8
post #4

Earlier quoted context omitted.

that's what I do and what the author recommends as well

Somehow I doubt DHH and company would be OK sacrificing ""developer experience"" for security... There is still a non-trivial amount of docker-compose files and Docker incantations that don't work 1:1 with podman and podman-compose. Adjusting them would require Omarchy's users underatanding podman, and I doubt this will align with the opinionated nature of Omarchy..

[deleted]
Post reply on HN