song4 最近的时间轴更新
song4's repos on GitHub
Rust · 2416 人关注
charming
A visualization library for Rust
Python · 7 人关注
LmlParser
A minimal parser for AWS API Gateway responding data.
Ruby · 4 人关注
FunTalk
The Fun Talk App
HCL · 3 人关注
google-cloud-service-agents
Exposes a list of service agents for given Google project.
2 人关注
awesome-handbooks
A curated list of awesome employee handbooks.
Rust · 2 人关注
birdie
Birdie is a third party Binance API client, allowing you to easily interact with the Binance API using Rust.
HTML · 2 人关注
CocoaShelf
Cocoa shelf
1 人关注
awesome-everything-as-code
A curated list of awesome everything-as-code tools, frameworks, and approaches.
Rust · 1 人关注
magic-cli
Command line utility to make you a magician in the terminal
JavaScript · 0 人关注
admin-on-rest
A frontend framework for building admin SPAs on top of REST services, using React and Material Design
Python · 0 人关注
adventofcode
Python · 0 人关注
adventofcode-2019
Java · 0 人关注
algs4
Algorithms, 4th edition textbook code and libraries
0 人关注
anata-no-minato
0 人关注
ansible-nginx
An Ansible role that installs Nginx.
HTML · 0 人关注
archived-blog
Rust · 0 人关注
asterinas
Asterinas is a secure, fast, and general-purpose OS kernel, written in Rust and providing Linux-compatible ABI.
0 人关注
Auto_Wordlists
Makefile · 0 人关注
awesome-kubernetes
A curated list for awesome kubernetes sources :ship::tada:
Perl · 0 人关注
bandwidth-guard
Bandwidth Guard for Shadowsocks
0 人关注
banzai-charts
Curated list of Banzai Cloud Helm charts used by the Pipeline Platform
Python · 0 人关注
Baymax
Baymax - Personal Data Metrics
0 人关注
black-hat-rust
Applied offensive security with Rust - Early access - https://academy.kerkour.com/black-hat-rust?coupon=GITHUB
C · 0 人关注
blink
tiniest x86-64-linux emulator
HTML · 0 人关注
blog
C · 0 人关注
bloom-filter
Implementation of Bloom Filter.
0 人关注
bloop
bloop is a fast code search engine written in Rust.
0 人关注
book-extreme-c
Assembly · 0 人关注
boot-programming
C · 0 人关注
Cherry
Python · 0 人关注
climb
Python library for interactive command line applications.
C · 0 人关注
clisp
Go · 0 人关注
cloudwatch_exporter
A CloudWatch exporter for Prometheus coded in Go, with multi-region support
0 人关注
code
Source code for the book Rust in Action
C++ · 0 人关注
codevs.cn
Vim script · 0 人关注
config-files
Copies of my config files.
0 人关注
container-networking
Container networking from scratch, from a single namespace to an overlay network.
Rust · 0 人关注
coreutils
Cross-platform Rust rewrite of the GNU coreutils
Python · 0 人关注
cpython
The Python programming language
0 人关注
craftinginterpreters
Repository for the book "Crafting Interpreters"
C · 0 人关注
csv2mdtable
Convert CSV string to markdown table.
0 人关注
DCA
Docker Certified Associate Exam Preparation Guide
0 人关注
dca-prep-guide
Docker Certification Associate preparation guide - a list of resources to help you prepare for a successful certification
Python · 0 人关注
demo-repo
A demo repo.
Go · 0 人关注
devops-challenge
Three DevOps tasks.
0 人关注
DevopsWiki
A wiki of Devops Tools, Tutorials and Scripts
Shell · 0 人关注
docker-gitlab
Dockerized GitLab
JavaScript · 0 人关注
docker.github.io
Source repo for Docker's Documentation
0 人关注
documentation-website
The documentation for OpenSearch, OpenSearch Dashboards, and their associated plugins.
0 人关注
dotfiles-1
There is no place like ~/
0 人关注
egui
egui: an easy-to-use immediate mode GUI in Rust that runs on both web and native
C++ · 0 人关注
electron
Build cross platform desktop apps with JavaScript, HTML, and CSS
Go · 0 人关注
exercise-golang
0 人关注
fd
A simple, fast and user-friendly alternative to 'find'
0 人关注
fish-shell
The user-friendly command line shell.
Rust · 0 人关注
fist
Python · 0 人关注
flask
A microframework based on Werkzeug, Jinja2 and good intentions
Python · 0 人关注
Flask-Boot
Create new Flask apps.
JavaScript · 0 人关注
FunDevBlog
Blog for the FunPlus dis team.
0 人关注
gauntlet
Raycast-inspired open-source application launcher with React-based plugins
Shell · 0 人关注
gb
C · 0 人关注
ghidra
Rust · 0 人关注
gimage
JavaScript · 0 人关注
git-hooks
Swift · 0 人关注
GithubStar
The missing Github star manager.
0 人关注
gitignore
A collection of useful .gitignore templates
JavaScript · 0 人关注
gitlab-treeview
Go · 0 人关注
go-echarts
🎨 The adorable charts library for Golang
Go · 0 人关注
go-gin-prometheus
Gin Web Framework Prometheus metrics exporter
0 人关注
go-perfbook
Thoughts on Go performance optimization
Go · 0 人关注
go-sudoku
Python · 0 人关注
gocode-subl3
Sublime Text 3 plugin for gocode
Go · 0 人关注
goweight
A tool to analyze and troubleshoot a Go binary size.
Shell · 0 人关注
grafana-dashboards
List of Grafana Dashboards 📺
C · 0 人关注
Grid
Mac window manager.
0 人关注
Hacking-Security-Ebooks
Top 100 Hacking & Security E-Books (Free Download) - Powered by Yeahhub.com
Rust · 0 人关注
heh
A terminal UI to edit bytes by the nibble.
0 人关注
helpdesk-bot
Swift · 0 人关注
higgs-swift
Higgs - the swift data tracker
Go · 0 人关注
illustrated-tls
The Illustrated TLS Connection: Every byte explained
C++ · 0 人关注
ImageFreak
0 人关注
interactive-tutorials
Interactive Tutorials
0 人关注
interview
Everything you need to prepare for your technical interview
JavaScript · 0 人关注
js-sudoku
0 人关注
jsonvisio.com
🧩 Visualize your JSON data onto graphs seamlessly.
C · 0 人关注
keepalived
Keepalived
Jsonnet · 0 人关注
kf-test
Go · 0 人关注
komiser
AWS Environment Inspector 👮
Go · 0 人关注
kops
Kubernetes Operations (kops) - Production Grade K8s Installation, Upgrades, and Management
0 人关注
krew
📦 Find and install kubectl plugins
0 人关注
krew-index
Plugin index for https://github.com/kubernetes-sigs/krew. This repo is for plugin maintainers.
0 人关注
kubernetes-networking-links
Kubernetes Networking recommended reading list
Go · 0 人关注
kubewatch
Watch k8s events and trigger Handlers
0 人关注
lfs-me
Linux From Scratch made ( more ) easy. A simple, fakeroot based, package manager for LFS heavily inspired by Archlinux' package management.
0 人关注
linux
Linux kernel source tree
0 人关注
linux-hardening-checklist
Simple checklist to help you deploying the most important areas of the GNU/Linux production systems - work in progress.
0 人关注
linux-re-101
A collection of resources for linux reverse engineering
0 人关注
loco
🚂 🦀 The one-person framework for Rust for side-projects and startups
0 人关注
Lua-Source-Internal
Lua source internal
song4

song4

我想到了一个绝妙的签名,可惜这里太小,写不下。
V2EX 第 57436 号会员,加入于 2014-03-05 13:05:50 +08:00
物理系出身,却干上了程序员的行当。

染指C++、Node.js、Python和Java。

喜好数学、物理、逻辑和哲学。

对于有同样爱好的童鞋,我只有一句话:请联系我。
[新加坡] HonestBee 招 DevOps/Backend/Frontend 工程师,你来不来?
酷工作  •  song4  •  2018-12-26 21:57:58 PM  •  最后回复来自 song4
14
出一些电脑配件
二手交易  •  song4  •  2017-07-09 07:48:31 AM  •  最后回复来自 song4
20
迫于搬家的重量,出一波书~
二手交易  •  song4  •  2017-07-14 23:37:34 PM  •  最后回复来自 xingstar
52
迫于生机,出 Macbook Pro 2015 版 15 寸 9 成以上新
二手交易  •  song4  •  2017-07-06 16:39:27 PM  •  最后回复来自 M1991madong
40
出一个只玩了三天的 Synology DS216j, 2800 大洋,可小刀,包邮
二手交易  •  song4  •  2017-07-02 15:43:35 PM  •  最后回复来自 lamls
12
[北京] 出一款九成新正版国行 15 寸 Macbook Pro
二手交易  •  song4  •  2015-02-11 22:01:47 PM  •  最后回复来自 EchoChan
39
song4 最近回复了
支持一下,想来新加坡的朋友们可以考虑一下。这枚 HR 超赞的。
2019-02-26 11:25:15 +08:00
回复了 rizon 创建的主题 程序员 关于借助 docker 获取 root 目录权限实现提权问题的探讨
先回答第一个问题:

> 如果 docker 中的用户名交 dockeruser 宿主机没有这个用户,他是怎么映射的呢?按照 uid 吗?

是的,按照 uid 来映射。默认从 uid=0 开始映射,宿主机的 uid=0,1,2,... 映射为容器的 uid=0,1,2,...。你可以通过 `--userns-remap` 选项来改变这个行为,比如说可以指定宿主机的 uid=1000,1001,1002,... 映射为容器的 uid=0,1,2,...。

第二个问题:

> 所以在容器内就是 root 权限了,怎么避免呢?

事实确实是这样的,你可以参考 LWN 的这篇文章:[User namespaces + overlayfs = root privileges]( https://lwn.net/Articles/671641/)。这一点其实在 Docker 官方给出的 [Docker daemon attack surface]( https://docs.docker.com/engine/security/security/) 中也已经指出来了:

> Docker allows you to share a directory between the Docker host and a guest container; and it allows you to do so without limiting the access rights of the container. This means that you can start a container where the /host directory is the / directory on your host; and the container can alter your host filesystem without any restriction. This is similar to how virtualization systems allow filesystem resource sharing. Nothing prevents you from sharing your root filesystem (or even your root block device) with a virtual machine.

那么,怎么避免呢?一种方案是,可以在运行容器的时候通过 `--user` 选项指定非 root 用户名和组。另外,挂载 volumes 的时候遵循 Principle of Least Privilege 是一个好习惯:尽量避免挂载系统重要的目录或文件,如果实在需要,不妨使用只读挂载。
2019-02-12 13:29:05 +08:00
回复了 ns2250225 创建的主题 程序员 请问怎样知道 k8s 的一个 node 最多能创建多少个 pod 呀 😭
@monsterxx03 是对的,做 Capacity Planning 的话,还需要知道应用的工作负载特征。
2018-12-26 21:57:58 +08:00
回复了 song4 创建的主题 酷工作 [新加坡] HonestBee 招 DevOps/Backend/Frontend 工程师,你来不来?
@abmin521 是的
2018-12-26 17:43:32 +08:00
回复了 song4 创建的主题 酷工作 [新加坡] HonestBee 招 DevOps/Backend/Frontend 工程师,你来不来?
我是 DevOps 工程师
2018-12-25 23:33:44 +08:00
回复了 song4 创建的主题 酷工作 [新加坡] HonestBee 招 DevOps/Backend/Frontend 工程师,你来不来?
@tyrealgray 这个应该好协调的吧,不清楚您当时的具体情况 😂
2018-12-25 23:28:14 +08:00
回复了 song4 创建的主题 酷工作 [新加坡] HonestBee 招 DevOps/Backend/Frontend 工程师,你来不来?
@mygoare 我们业务中用到的是 React,如果你学习能力足够强,欢迎投递简历!
2018-12-25 23:23:18 +08:00
回复了 song4 创建的主题 酷工作 [新加坡] HonestBee 招 DevOps/Backend/Frontend 工程师,你来不来?
@jishu541464750 你够了。。。
2018-12-12 15:57:48 +08:00
回复了 summersnow521 创建的主题 Java Java DevOps 最贱实践讨论
你是想讨论“最贱实践”还是“最佳实践”?
关于   ·   帮助文档   ·   自助推广系统   ·   博客   ·   API   ·   FAQ   ·   Solana   ·   853 人在线   最高记录 6679   ·     Select Language
创意工作者们的社区
World is powered by solitude
VERSION: 3.9.8.5 · 44ms · UTC 20:44 · PVG 04:44 · LAX 12:44 · JFK 15:44
♥ Do have faith in what you're doing.