Re: Automatic service jails - review request
Alexander Leidinger <[email protected]>
| Newsgroups | gmane.os.freebsd.architechture |
|---|---|
| Message-ID | <20230602112930.Horde.JM5vGJ2ftpR0pxFB69Zi3z_@webmail.leidinger.net> |
Quoting Gleb Popov <[email protected]> (from Thu, 1 Jun 2023 14:35:46 +0300): > On Thu, Jun 1, 2023 at 1:25 PM Alexander Leidinger > <[email protected]> wrote: >> >> Hi, >> >> I implemented a functionality which allows to automatically put rc.d >> services into jails. > > THis is highly related to what I did in > https://github.com/freebsd/freebsd-ports/tree/main/ports-mgmt/rc-subr-jail > although my approach isn't automatic in any way. When you committed that I had a very quick look. I understand it as follows: - my stuff: low security, higher security than no jail, very easy to setup - your stuff: medium security, higher than what I do (due to a separate FS), more work required to setup - one service per vnet-jail, manual setup required: full security, much more setup work And I think our stuff is complementary. As I understand it by a quick look, your code would be used inside a rc.d script to setup a jail tailored to the service, whereas my code doesn't need any change to rc.d scripts in the most easy case, and could life with only rc.conf entries for the service, but 1 config change to the rc.d service would make it self-contained. Bye, Alexander. -- http://www.Leidinger.net [email protected]: PGP 0x8F31830F9F2772BF http://www.FreeBSD.org [email protected] : PGP 0x8F31830F9F2772BF
signature.asc
(application/pgp-signature, 851 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIzBAABCAAdFiEER9UlYXp1PSd08nWXEg2wmwP42IYFAmR5tnoACgkQEg2wmwP4 2Ibt+w/9EYh3AHBe2srDM/hfrC9H28nFjHMOcA4zKV64oobR3RNpd7YMiJT1aYOT mDF005oss8YSFiGzfwOixUqxVditW4GP1oPsphHuicIF/0WGbQs9dGcKqz3zDQzK 7JNt3uvU8SjgRP5QtUxLBBj8R0WFaEK5Y6knJQ8dNajQIG8DVRFDlzPO2MqnRxzi VTu7zyocni/P2bT9TqX0I/sDvFKHnlc89dSeIg/v8ubFAzEMvmrXGSLmBYKGAa6x 4R3+w8lPLq4zGsu9OzTC4H2sqKqJ7Kx2cDbjyi29Dy1S5GP0kkPj/OiRymqdS0zd mS6Lqy8jRmNa69xbBWyI1fYMEw7JNFOFaCm0jBa3eQdSELqYbcozMbbTa0DtqdLW 567i0S+BPZyDTYpQ8oB3dq/Z0AtsqbhlKvZBsvKYaLB28NCqU/pkIID+os0k/6LR TEVeK7vLxXHos+dKCjIrltGW81a68UNFVyMPcgZdqY2CI+XMlE02TZGHa1GVq6mS K2XUkZM0AwhTf51gQ+/wHQy8+IPI8ZS/XZCW/MKJzMhNG07RXS+sszWBX5Oryb1x 2uWe5QFRcaCmKpFsZ57CnhWr0Rk+wdTOacbbod7WqxZExDTnd6/1EWTfND0Wbbfe ggxQEAKZGceGO1MTy9PPpUf21o2thaGukJneO2fb1k8CTeQpgUk= =Ia3S -----END PGP SIGNATURE-----