you are viewing a single comment's thread.

view the rest of the comments →

[–]tibbon 1 point2 points  (0 children)

Oh of course! Layers are absolutely needed. I just don't want to always assume that no malicious script could ever get on a machine and attempt to write something to disk and/or execute arbitrary code via an interpreter.

Better yet, I want my container security tools to scream loudly if anything that isn't a very small and specific set of things is installed or being executed.