On Thu, Sep 24, 2026 at 2:03 PM Wietse Venema via Postfix-users
<[email protected]> wrote:
>
> Wietse Venema via Postfix-users:
> > In a "No new privs" world, the set-gid feature becomes unavailable,
> > and must be replaced with authenticated IPC (inter-process
> > communication). This may be facilitated with systemd-managed sockets
> > that launch client programs with suitable privileges.
>
> How would that work with Postfix in a container? This solution would
> make systemd a hard dependency, breaking configurations where Postfix
> currtently runs as PID=1.

Who should call these tools in a container?
postfix is only reachable via network ports, not via sockets.
And the only user who has access to the container is root.

Thorsten

-- 
Thorsten Kukuk, Distinguished Engineer, Future Technologies
SUSE Software Solutions Germany GmbH, Frankenstraße 146, 90461
Nuernberg, Germany
Geschäftsführer: Stefan Gaiser, Jochen Jaser, Abhinav Puri (HRB 36809,
AG Nürnberg)
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to