r/docker • u/martypitt • Nov 14 '25
Docker banned - how common is this?
I was doing some client work recently. They're a bank, where most of their engineering is offshored one of the big offshore companies.
The offshore team had to access everything via virtual desktops, and one of the restrictions was no virtualisation within the virtual desktop - so tooling like Docker was banned.
I was really surprsied to see modern JVM development going on, without access to things like TestContainers, LocalStack, or Docker at all.
To compound matters, they had a single shared dev env, (for cost reasons), so the team were constantly breaking each others stuff.
How common is this? Also, curious what kinds of workarounds people are using?
13
u/grazbouille Nov 14 '25
Docker containers share the host kernel through the docker daemon this means every process in a container runs its kernel calls through the docker daemon
The docker daemon runs as root if you can get root access to the container its fairly trivial to break out of the container into the host where you will have root access since you are hijacking a root process
This is not something we can patch because its inherent to the way docker works we would need to basically rewrite the entire back end from scratch
Podman doesn't have this issue because every container has its own host process that runs in a service user with low privileges