• Sources: primary
  • Summary: Portainer states that the Docker Engine API exposes no primitives to scope API access below root on the host, so it lacks the fine-grained authorization Kubernetes provides. New investment in AI workloads, GPU scheduling, and workload sandboxing will therefore land only for Kubernetes users. Portainer 3.0 continues to support the existing Docker and Swarm feature set, states it will not regress it, and will keep tracking Docker security fixes.
  • Why it matters: Teams standardized on Docker Engine through Portainer keep what they run today but will not receive the new scheduling and sandboxing capabilities without moving to Kubernetes.

send feedback on this story