Dnia 24.09.2026 o godz. 08:03:30 Wietse Venema via Postfix-users pisze: > Wietse Venema via Postfix-users: > > In a "No new privs" world, the set-gid feature becomes unavailable, > > and must be replaced with authenticated IPC (inter-process > > communication). This may be facilitated with systemd-managed sockets > > that launch client programs with suitable privileges. > > How would that work with Postfix in a container? This solution would > make systemd a hard dependency, breaking configurations where Postfix > currtently runs as PID=1.
The goal of a containerized solution is to isolate the service that's running in a container from anything else, so I think using "No new privs" feature in a container has no sense. Should it protect the service from itself? This should be turned off in a container. -- Regards, Jaroslaw Rafa [email protected] -- "In a million years, when kids go to school, they're gonna know: once there was a Hushpuppy, and she lived with her daddy in the Bathtub." _______________________________________________ Postfix-users mailing list -- [email protected] To unsubscribe send an email to [email protected]
