On Thu, Sep 24, 2026 at 2:37 PM postfix--- via Postfix-users
<[email protected]> wrote:
>
> On 2026-09-24 08:03, Wietse Venema via Postfix-users wrote:
> > Wietse Venema via Postfix-users:
> >> In a "No new privs" world, the set-gid feature becomes unavailable,
> >> and must be replaced with authenticated IPC (inter-process
> >> communication). This may be facilitated with systemd-managed sockets
> >> that launch client programs with suitable privileges.
> >
> > How would that work with Postfix in a container? This solution would
> > make systemd a hard dependency, breaking configurations where Postfix
> > currtently runs as PID=1.
>
> I was wondering exactly the same.  I have not done detailed research,
> but from my limited experience running Postfix containerized in Alpine
> Linux vs. running it containerized in a systemD distro cost an extra
> 300MB RAM, in addition to the configuration issues.

You are doing something wrong here. It doesn't matter if your
container runs on Alpine or a containerized systemdD distro, why
should that matter?
And which configuration issues? Neither docker nor podman nor k8s
depends on systemD. Except you have to create a systemd service for
them, but at least podman does not for you automatically.
Or do you mean configuring postfix itself? Yes, this depends on the
author of the postfix container.
My postfix container needs 164MB additional disk space (though the
base image is shared with many other containers, so in reality it's
much less) and at runtime it requires the same amount of memory as if
I would run it directly on the system, at least if the libraries are
identical to the host. If they differ, you need of course more memory
because the kernel cannot share the libraries with other processes.

Thorsten

> SystemD (JournalD) is also a bad choice for server logs.  On the other
> hand, on my new desktop (CachyOS) current laptop (Pop!_OS) legacy
> desktop (Xubuntu) and home controller (Raspberry Pi) it's a legit choice.
>
> Have you considered that the isolation is not just privileges, but also
> network/location? why not using traditional sockets, including unix
> sockets and network sockets?  I like the way I can access my MariaDB
> instances, and I have considered whether it makes sense to
> install/configure Postfix on my OpenWrt mobile router (current answer:
> no, I have not found a good use case for that).  The key consideration
> for me is to reduce the exposure of email messages, in transit and at rest.
>
> I hope this helps your reflection, and I am sorry for not having more
> time to dig into the details,
>
> Yuv
> _______________________________________________
> Postfix-users mailing list -- [email protected]
> To unsubscribe send an email to [email protected]



-- 
Thorsten Kukuk, Distinguished Engineer, Future Technologies
SUSE Software Solutions Germany GmbH, Frankenstraße 146, 90461
Nuernberg, Germany
Geschäftsführer: Stefan Gaiser, Jochen Jaser, Abhinav Puri (HRB 36809,
AG Nürnberg)
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to