On 2026-09-24 08:03, Wietse Venema via Postfix-users wrote:
Wietse Venema via Postfix-users:
In a "No new privs" world, the set-gid feature becomes unavailable,
and must be replaced with authenticated IPC (inter-process
communication). This may be facilitated with systemd-managed sockets
that launch client programs with suitable privileges.

How would that work with Postfix in a container? This solution would
make systemd a hard dependency, breaking configurations where Postfix
currtently runs as PID=1.

I was wondering exactly the same. I have not done detailed research, but from my limited experience running Postfix containerized in Alpine Linux vs. running it containerized in a systemD distro cost an extra 300MB RAM, in addition to the configuration issues.

SystemD (JournalD) is also a bad choice for server logs. On the other hand, on my new desktop (CachyOS) current laptop (Pop!_OS) legacy desktop (Xubuntu) and home controller (Raspberry Pi) it's a legit choice.

Have you considered that the isolation is not just privileges, but also network/location? why not using traditional sockets, including unix sockets and network sockets? I like the way I can access my MariaDB instances, and I have considered whether it makes sense to install/configure Postfix on my OpenWrt mobile router (current answer: no, I have not found a good use case for that). The key consideration for me is to reduce the exposure of email messages, in transit and at rest.

I hope this helps your reflection, and I am sorry for not having more time to dig into the details,

Yuv
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to