sshiv012 commented on PR #7172:
URL: https://github.com/apache/texera/pull/7172#issuecomment-5245618958

   @Yicong-Huang could you clarify whether these runners use rootless Docker or 
the conventional root-owned Docker socket? I initially read the lack of sudo 
and privileged as meaning the jobs were unprivileged, but Docker documents that 
access through the normal docker group is effectively root-level host access. 
I'd like to believe it's rootless dockerd or Podman because there'd be no 
long-lived daemon. Asking because on a non-ephemeral runner the runner process 
runs as that user and receives the next job's secrets, so rootless lowers the 
ceiling without removing the cross-job path.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to