错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Docker and Podman

  • Marco Antonio Carcano

摘要

Abstracting container runtimes as secure, unexamined environments introduces critical vulnerabilities into production layers. Modern DevSecOps engineering requires far more than wrapping software inside default container images; it demands absolute control over infrastructure execution. This chapter delivers an applied, execution-focused analysis of Docker and Podman, constructing a localized ecosystem to master secure container workflows. Moving past basic runtime initialization, you will learn how to inspect remote registries utilizing Skopeo, implement advanced container checkpointing, and refactor a legacy enterprise service into a hardened, compliant container image. This framework eliminates hazardous root-privilege defaults and aligns container lifecycles with strict operating-system-level compliance, providing the foundational skills required to secure and optimize modern enterprise deployment pipelines.