3 ms·
> the security aspect It’s not a systemd-specific thing, but systemd makes it relatively easy to drop privileges (like network in this case), whilst also allow
by ratorx 1y ago
> the security aspect
It’s not a systemd-specific thing, but systemd makes it relatively easy to drop privileges (like network in this case), whilst also allowing socket-activated services to be configured easily. You can probably achieve the same thing with inetd + network namespaces (I think this is what systemd uses under the hood)
- eriksjolund 1y agoYou can use the podman option `--network=none` together with the systemd directive `RestrictAddressFamilies=` I wrote a demo: https://www.redhat.com/en/blog/podman-systemd-limit-access https://www.redhat.com/en/blog/podman-systemd-limit-access Podman will then not have the privilege to pull the container image, but a web server container can still serve the internet with socket activation.
- rendaw 1y agoWhat's the use case for that? Multitenant server web hosting where customers provide containers and you want to lock them down I guess? Mostly SaaS/PaaS?
- eriksjolund 1y agoI did it out of pure interest, just to explore ways of locking down a web server.
- rendaw 1y agoOh, fair enough! It is very cool, FWIW.