this post was submitted on 28 Apr 2025
263 points (95.8% liked)

Selfhosted

46426 readers
727 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
263
What is Docker? (lemmy.world)
submitted 2 days ago* (last edited 2 days ago) by Jofus@lemmy.world to c/selfhosted@lemmy.world
 

Hi! Im new to self hosting. Currently i am running a Jellyfin server on an old laptop. I am very curious to host other things in the future like immich or other services. I see a lot of mention of a program called docker.

search this on The internet I am still Not very clear what it does.

Could someone explain this to me like im stupid? What does it do and why would I need it?

Also what are other services that might be interesting to self host in The future?

Many thanks!

EDIT: Wow! thanks for all the detailed and super quick replies! I've been reading all the comments here and am concluding that (even though I am currently running only one service) it might be interesting to start using Docker to run all (future) services seperately on the server!

you are viewing a single comment's thread
view the rest of the comments
[–] jagged_circle@feddit.nl 3 points 1 day ago* (last edited 50 minutes ago) (1 children)

Package managers like apt use cryptography to check signatures in everything they download to make sure they aren't malicious.

Docker doesn't do this. They have a system called DCT but its horribly broken (not to mention off by default).

So when you run docker pull, you can't trust anything it downloads.

[–] Darioirad@lemmy.world 1 points 8 hours ago (1 children)

Thank you very much! For the off by default part i can agree, but why it's horribly broken?

[–] jagged_circle@feddit.nl 1 points 50 minutes ago* (last edited 48 minutes ago)

PKI.

Apt and most release signing has a root of trust shipped with the OS and the PGP keys are cross signed on keyservers (web of trust).

DCT is just TOFU. They disable it because it gives a false sense of security. Docker is just not safe. Maybe on 10 years they'll fix it, but honestly it seems like they just dont care. The well is poisoned. Avoid. Use apt or some package manager that actually cares about security