Skip to content

Does "containerized socket activation" improve security? #13390

Answered by rhatdan
eriksjolund asked this question in Q&A
Discussion options

You must be logged in to vote

I like the way you talk about this from a security point of view. The --network=none with socket activation seems like a great idea.

I could see this being useful with a display only webserver for example. Where you could allow incoming connections not not allow connections back out. But this would only work with TCP connections.

Replies: 7 comments 25 replies

Comment options

You must be logged in to vote
4 replies
@eriksjolund
Comment options

@rhatdan
Comment options

@eriksjolund
Comment options

@eriksjolund
Comment options

Answer selected by eriksjolund
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
1 reply
@eriksjolund
Comment options

Comment options

You must be logged in to vote
3 replies
@eriksjolund
Comment options

@rhatdan
Comment options

@eriksjolund
Comment options

Comment options

You must be logged in to vote
15 replies
@eriksjolund
Comment options

@eriksjolund
Comment options

@rhatdan
Comment options

@eriksjolund
Comment options

@eriksjolund
Comment options

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
2 replies
@zeronumbers
Comment options

@eriksjolund
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants