Re: [PATCH ghak90 V6] fixup! audit: add containerid filtering

2019-06-04 Thread Paul Moore
On Tue, Jun 4, 2019 at 3:55 AM Daniel Walsh wrote: > The need for nested container support is the `Enemy of the good`. This > idea has been being worked on for years and has always been blocked by > this seldom used feature. Speaking with some of the LXC folks, nested orchestrators isn't a seldo

Re: [PATCH ghak90 V6] fixup! audit: add containerid filtering

2019-06-04 Thread Daniel Walsh
The need for nested container support is the `Enemy of the good`.  This idea has been being worked on for years and has always been blocked by this seldom used feature. We are working on a project right this summer to allow us to use the audit system to track the syscalls used by a container and t