-
Notifications
You must be signed in to change notification settings - Fork 0
Service sandboxing #8
Copy link
Copy link
Open
Description
Some services (e.g. nginx) don't support running in a chroot directly. For those services there should be options in the service configuration to set up a chroot (or preferably namespace & cgroup) jail.
Such services will need their own binary, their libraries, their configuration and possible some device nodes bind mounted into the jail.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels