Re: [systemd-devel] nspawn: how to allow containers to connect to a specific host's port and prevent all the rest ?

2017-03-31 Thread Lennart Poettering
On Tue, 07.03.17 10:02, Fabien Meghazi (f...@odoo.com) wrote: > Hello everyone, > > I would like to constraint the network in the containers I spawn using > nspawn. > What I'd like to achieve is the following: > > - prevent the containers to use the network interfaces of the host > - make one

[systemd-devel] nspawn: how to allow containers to connect to a specific host's port and prevent all the rest ?

2017-03-07 Thread Fabien Meghazi
Hello everyone, I would like to constraint the network in the containers I spawn using nspawn. What I'd like to achieve is the following: - prevent the containers to use the network interfaces of the host - make one exception and allow the containers to connect (tcp) to a specific port bound on