postfix--- via Postfix-users:
> On 2026-09-24 08:03, Wietse Venema via Postfix-users wrote:
> > Wietse Venema via Postfix-users:
> >> In a "No new privs" world, the set-gid feature becomes unavailable,
> >> and must be replaced with authenticated IPC (inter-process
> >> communication). This may be facilitated with systemd-managed sockets
> >> that launch client programs with suitable privileges.
> > 
> > How would that work with Postfix in a container? This solution would
> > make systemd a hard dependency, breaking configurations where Postfix
> > currently runs as PID=1.

If we consider Postfix container deployment with PID=1, then there
should be no other processes in that container that may need to
send email before Postfix starts up.

More relevant, the only user running Postfix commands in such a
container should be root, so there should be no need for the setgid
privilege boost that a non-root user needs.

(I've added this to draft text for future postmux documentation).

        Wietse
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to