4 ms·
Podman quadlet supports "Socket activation of containers" https://github.com/containers/podman/blob/main/docs/tutorials/socket_activation.md#socket-activation-o
by eriksjolund 1y ago
Podman quadlet supports "Socket activation of containers" https://github.com/containers/podman/blob/main/docs/tutorials/socket_activation.md#socket-activation-of-containers https://github.com/containers/podman/blob/main/docs/tutorial...
This allows you to run a network server with `Network=none` (--network=none). If the server would be compromised, the intruder would not have the privileges to use the compromised server as a spam bot. There are other advantages, such as support for preserved source IP address and better performance when running a container with rootless Podman + Pasta in a custom network.
- infogulch 1y agoThat's neat. Does it require 1 connection = 1 process to work? I don't see how you can have a long running server with this feature.
- deleted 1y ago[deleted]
- xyzzy_plugh 1y agoNo, the init process hands over the listener FD allowing the server to accept() connections. You can also do 1 connection = 1 process, though, but it's absolutely not required nor particular common these days.
- anonfordays 1y agoWhat's old is new again. That's effectively how inetd worked circa 1986. The inetd daemon had some serious security vulnerabilities so the world move away from using "socket activated daemons" to having always listening services (performance reasons as well).
- thwarted 1y agoinetd supported "socket activation" using the "wait" directive, where inetd would listen on the socket and then hand off the listening socket when there was activity as fd 0 where the server would need to call accept, and could continue to call accept for new connections, or exit when all clients were handled, and inetd would respawn when there was new pending connection on the listening socket.
- rendaw 1y agoI never understood the use case for socket activation - is someone really running a web server that mixed workloads, long periods with no network traffic you'd rather prioritize something else, and a web server that's so resource intensive when not handling events it makes sense to stop it? Maybe desktop computers? The security aspect is something new to me and I'm not sure if that applies to inetd/systemd socket services or if it's specifically a container thing. Does anyone have more info on use cases for this?
- ratorx 1y ago> the security aspect It’s not a systemd-specific thing, but systemd makes it relatively easy to drop privileges (like network in this case), whilst also allowing socket-activated services to be configured easily. You can probably achieve the same thing with inetd + network namespaces (I think this is what systemd uses under the hood)
- eriksjolund 1y agoYou can use the podman option `--network=none` together with the systemd directive `RestrictAddressFamilies=` I wrote a demo: https://www.redhat.com/en/blog/podman-systemd-limit-access https://www.redhat.com/en/blog/podman-systemd-limit-access Podman will then not have the privilege to pull the container image, but a web server container can still serve the internet with socket activation.
- rendaw 1y agoWhat's the use case for that? Multitenant server web hosting where customers provide containers and you want to lock them down I guess? Mostly SaaS/PaaS?
- eriksjolund 1y agoI did it out of pure interest, just to explore ways of locking down a web server.