On Thu, Sep 24, 2026 at 2:03 PM Wietse Venema via Postfix-users <[email protected]> wrote: > > Wietse Venema via Postfix-users: > > In a "No new privs" world, the set-gid feature becomes unavailable, > > and must be replaced with authenticated IPC (inter-process > > communication). This may be facilitated with systemd-managed sockets > > that launch client programs with suitable privileges. > > How would that work with Postfix in a container? This solution would > make systemd a hard dependency, breaking configurations where Postfix > currtently runs as PID=1.
Who should call these tools in a container? postfix is only reachable via network ports, not via sockets. And the only user who has access to the container is root. Thorsten -- Thorsten Kukuk, Distinguished Engineer, Future Technologies SUSE Software Solutions Germany GmbH, Frankenstraße 146, 90461 Nuernberg, Germany Geschäftsführer: Stefan Gaiser, Jochen Jaser, Abhinav Puri (HRB 36809, AG Nürnberg) _______________________________________________ Postfix-users mailing list -- [email protected] To unsubscribe send an email to [email protected]
