Why not use rootless podman? It is 2026 not 2016, Podman works much better than Docker today.
Omarchy: Any User Process Can Escalate to Root
21–30 of 583 posts
Re: Omarchy: Any User Process Can Escalate to Root
#22Is it not better to run a VM just for Docker, like we have to do on macOS?
Re: Omarchy: Any User Process Can Escalate to Root
#23It’s not great, but I’m not sure this should be framed as Omarchy-specific, when it’s a very common setup to add regular user to the docker group.
Re: Omarchy: Any User Process Can Escalate to Root
#24(example: NetworkChuck, Primeagen? and a few others)
also, archlinux is much easier to install nowadays with archinstall [1], so i'm not sure you really need another opinionated layer on top of it
Re: Omarchy: Any User Process Can Escalate to Root
#25Re: Omarchy: Any User Process Can Escalate to Root
#26I was expecting a more sophisticated attack and then I scrolled down… > Omarchy configured its default user as a member of the Linux docker group. What the fuck? Docker makes it VERY, VERY clear this is unsafe. Feel free to verify the documentation. https://docs.docker.com/engine/install/linux-postinstall/ Why would you want to make this the default for your users, without even telling them? Did someone configured hi…
Re: Omarchy: Any User Process Can Escalate to Root
#27It’s not great, but I’m not sure this should be framed as Omarchy-specific, when it’s a very common setup to add regular user to the docker group.
>when it’s a very common setup to add regular user to the docker group. As an official configuration? Or in random copy paste guides? The former is very different than the latter. It's not uncommon to disable sudo passwords, but it would be considered a serious security lapse if that were the default on some OS.
Re: Omarchy: Any User Process Can Escalate to Root
#28It’s not great, but I’m not sure this should be framed as Omarchy-specific, when it’s a very common setup to add regular user to the docker group.
>when it’s a very common setup to add regular user to the docker group. As an official configuration? Or in random copy paste guides? The former is very different than the latter. It's not uncommon to disable sudo passwords, but it would be considered a serious security lapse if that were the default on some OS.
Re: Omarchy: Any User Process Can Escalate to Root
#29Is it not better to run a VM just for Docker, like we have to do on macOS?
Re: Omarchy: Any User Process Can Escalate to Root
#30It’s not great, but I’m not sure this should be framed as Omarchy-specific, when it’s a very common setup to add regular user to the docker group.
>when it’s a very common setup to add regular user to the docker group. As an official configuration? Or in random copy paste guides? The former is very different than the latter. It's not uncommon to disable sudo passwords, but it would be considered a serious security lapse if that were the default on some OS.