Dnia 24.09.2026 o godz. 08:03:30 Wietse Venema via Postfix-users pisze:
> Wietse Venema via Postfix-users:
> > In a "No new privs" world, the set-gid feature becomes unavailable,
> > and must be replaced with authenticated IPC (inter-process
> > communication). This may be facilitated with systemd-managed sockets
> > that launch client programs with suitable privileges.
> 
> How would that work with Postfix in a container? This solution would
> make systemd a hard dependency, breaking configurations where Postfix
> currtently runs as PID=1.

The goal of a containerized solution is to isolate the service that's
running in a container from anything else, so I think using "No new privs"
feature in a container has no sense. Should it protect the service from
itself? This should be turned off in a container.
-- 
Regards,
   Jaroslaw Rafa
   [email protected]
--
"In a million years, when kids go to school, they're gonna know: once there
was a Hushpuppy, and she lived with her daddy in the Bathtub."
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to