You are not logged in.

#1 2023-12-11 11:05:47

warteeminus321
Member
Registered: 2022-09-03
Posts: 27

Proper way to secure an nspawn container with SELinux?

There are -Z and -L options to boot an nspawn container that are selinux-related...https://man.archlinux.org/man/systemd-nspawn.1.en#Security_Options I don't see any systemd-selinux policies related to nspawn https://github.com/archlinuxhardened/se … md-selinux
The question is: what is the proper way to secure nspawn containers with SELinux on SELinux enabled Arch installations?


Hitchhacker's Guide to the Galaxy: “Nothing travels faster than the speed of light with the possible exception of bad news, which obeys its own special laws.”
If you didn't know you are backdoored, you are backdoored.

Offline

#2 2023-12-11 11:11:00

warteeminus321
Member
Registered: 2022-09-03
Posts: 27

Re: Proper way to secure an nspawn container with SELinux?

Or is running a QEMU instance with a full selinux-enabled install the only way to get an SELinux secured container at this time?


Hitchhacker's Guide to the Galaxy: “Nothing travels faster than the speed of light with the possible exception of bad news, which obeys its own special laws.”
If you didn't know you are backdoored, you are backdoored.

Offline

Board footer

Powered by FluxBB