3 ms·
Echoing this. All the services on my servers (Web, Gemini, Matrix, Fediverse servers and a CSP violations collector) are statically-linked binaries running in s
by Seirdy 5y ago
Echoing this. All the services on my servers (Web, Gemini, Matrix, Fediverse servers and a CSP violations collector) are statically-linked binaries running in sandboxed chroots, with no access to the outside filesystem except a subdir of my data volume mounted into the chroot. Privs are limited to a defined list of acceptable syscalls and other limitations. I'm currently working on enforcing the use of this setup with SELinux policies and transitioning my OCSP fetching and session ticket key rotating scripts to statically linked binaries so I can just stick to one template shared across all services.
It would have been much harder to pull this off if these services required large interpreters, adjacent daemons running, and complex orchestration. Given the amount of time I have, I might have just skipped the SELinux step.