Multi-container docker configuration is presently mired in complexity (examples: confd, gantryd) in part because docker makes it hard to deterministically assign addresses to containers. As a result, service- discovery must be done via dynamic control and agreement at “network run time”instead of at “network compile time”. Potential solutions:
Translation, “problematisation”, “interessement”, “enrolment”, “mobilisation”, “boundary objects”, “data-information-knowledge-control”, and friends:
Impossibility results, information flow control, non-interference, and inference control:
Most of the world uses unfortunate definitions for words like “identity” and “authentication” but my current preferred definitions:
identity: a cluster of nyms
authentication: a guarantee that, at the end of a protocol, some principals agree on a mapping of symbols to values
are way too surprising to reasonably be called "identity" or "authentication". (What to do!?)