3 ms·
All the declarative security sandboxing stuff. Last I checked openrc doesn't let you easily run a service in a process or network namespace. Or filter syscalls
by RVuRnvbM2e 2y ago
All the declarative security sandboxing stuff. Last I checked openrc doesn't let you easily run a service in a process or network namespace. Or filter syscalls etc.
I also make heavy use of user services, TPM encrypted secrets, systemd tmpfile directories, etc.
Another thing: systemd-networkd is the only Linux networking stack I've managed to get working reliably with tailscale's dns and a private dns service on my workstation.
- djbusby 2y agoOh yeah, I forgot about that tmpfiles feature - that one is useful