4 ms·
The new Firejail app [1] may be worth exploring as it is designed to run locally installed apps like browsers and games in sandboxes, as opposed to more chroot
by tobbyb 11y ago
The new Firejail app [1] may be worth exploring as it is designed to run locally installed apps like browsers and games in sandboxes, as opposed to more chroot oriented container managers like LXC, Docker or Nspawn. They all use namespaces.
If you want to use a chroot oriented container manager its better to use an unprivileged container so you are not running as root. Currently only LXC has support for unprivileged containers. We have an experimental GUI app container with Chrome that can be used in unprivileged mode. [2]
You can even run your own sandbox with a simple command like this 'unshare -fp --mount-proc' That gives you a bash shell in its own pid space. You can expand this command further to use more namespaces like mount, net, user to get yourself a sandbox.
That is what apps like firejail and container managers are using, but its useful to know what's happening underneath. We are currently working on a guide on how to use unshare that may help. [3]
[1] https://l3net.wordpress.com/projects/firejail/ https://l3net.wordpress.com/projects/firejail/
[2] https://www.flockport.com/apps/lxc-gui/ https://www.flockport.com/apps/lxc-gui/
[3] https://www.flockport.com/how-linux-containers-work/ https://www.flockport.com/how-linux-containers-work/