Re: configure bind in chroot jail

Fred Morris <[email protected]>
Newsgroups gmane.network.dns.bind9.user
Message-ID <alpine.LSU.2.21.2508010753110.21920__8256.16746894724$1754060477$gmane$org@flame.m3047>
To add to what Greg says..

On Fri, 1 Aug 2025, Greg Choules via bind-users wrote:
>
> I would suggest that, if you are really worried about losing control of a
> process, or it being used for remote access to your machine, or
> something (are either of these why you think you need chroot?) you should
> either/both run BIND in a VM or take a good look at your server and network
> security.

KVM virtualization is pretty much out of the box. Docker isn't hard. Since 
you are running on Linux, are you aware that systemd has its own kind of 
containerization which builds on features of the modern Linux kernel? Take 
a look at systemd-nspawn. (man systemd-nspawn) I don't have a playbook for 
you, unfortunately.

--

Fred Morris, internet plumber

-- 
Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list

ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information.


bind-users mailing list
[email protected]
https://lists.isc.org/mailman/listinfo/bind-users
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.