4 ms·
I'm using them for several things but the most straightforward one is probably that namespacing can be gradually added to services, you most likely see benefits
by shatteredgate 5y ago
I'm using them for several things but the most straightforward one is probably that namespacing can be gradually added to services, you most likely see benefits from this already if you use systemd. That's one way that namespaces can be used in a different way from the docker model.
- ori_b 5y agoWhat are you adding gradually, specifically? Like, a concrete example that names a namespace you may want to use. I'm trying to figure out what problems a half sandbox solves, and a vague "I just want to enable some capabilities" doesn't help here.
- shatteredgate 5y agoA lot of the various security options in systemd: https://www.freedesktop.org/software/systemd/man/systemd.exec.html https://www.freedesktop.org/software/systemd/man/systemd.exe... The sandboxing and mount-related ones are implemented with namespaces, and the idea with them is to not make any of them mandatory so they can be slowly added to system services. That way you can get some of the benefits without needing to build a full rootfs/container for the service. I am not sure how any of those would be done with jails because jails require you to create a chroot and network interface, whereas in Linux the mount and network namespaces are just optional namespaces and you can still use the other namespaces without using them.
- shatteredgate 5y agoSide note: I suppose you could chroot to /.
- philkrylov 5y ago> jails require you to create a chroot and network interface, They don't: you may chroot to /, share the host's network interface, or disable networking.
- kazen44 5y agoalso, with epairs you can do some really flexible networking stuff on freebsd between jails/jails and the host system and even jails and ipsec tunnels.
- trasz 5y agoIt's literally a single command: trasz@v3:~ % doas jail / foo 127.0.0.1 /bin/sh # ps aux USER PID %CPU %MEM VSZ RSS TT STAT STARTED TIME COMMAND root 37975 0,0 0,0 13500 3056 3 SJ 09:11 0:00,01 /bin/sh root 37976 0,0 0,0 13624 2776 3 R+J 09:11 0:00,00 ps aux