Docker docker docker docker docker docker docker docker docker.
Some good nuggets but fuck docker.
I am not a fan of docker. I manage things with Ansible/TF/etc. I can rebuild a server in a few minutes. I don't want to rely on a possibly rooted container or something or spend time to build my own.
I am not either. My career at its current level is specializing automation via Ansible, and for everything else the shell can handle it. Docker always just introduces problems, and I haven't seen one example where it produced a solution.
This is exactly the issue I was screaming about for years. Finally there was a breach. If you can think it can happen.It will happen.
The day they started pushing that shit I was saying "are you fucking stupid or something"? If you don't control the entire stack you cannot assume it is not compromised. Even then, insider threat is a thing and a BIG thing at that.
Letting "devs" control deploying the framework everything runs on is one of the dumbest ideas on the planet. I would suggest it's like giving a 2 year old the control for a massive dam and they get to make it do things because they think it's funny while people downstream die.
The best of them sort of know what they are doing. The rest are "you get in my way of deploying my shit code that I don't test properly that will fuck up your entire week".