[tomoyo-users-en 713] tomoyo with docker

Back to archive index
Luigi Tarantino l.tar****@gmail*****
Mon Aug 26 17:49:38 JST 2019


Hello,
  Can tomoyo play nicely with container technologies like docker?

In other words is it possible to deploy a tomoyo policy that only applies
to a specific container?
This would mean that a process in the container may for example issue an
open("/etc/x.conf", ...), in its own mount namespace, and I want to allow
that open only in that container, but not for instance in the host (where
"/etc/x.conf" is a different file, if it exists), or in other containers
running on the same host.

Thanks,
  Vincenzo
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.osdn.me/mailman/archives/tomoyo-users-en/attachments/20190826/7532c1a5/attachment.html>


More information about the tomoyo-users-en mailing list
Back to archive index