firecracker-microvm/firecracker

Investigate running the jailer with reduced set of capabilities

Aberta

#1.190 aberto em 22 de jul. de 2019

 (6 comentários) (0 reação) (1 responsável)Rust (2.393 forks)batch import
Good first issuePriority: LowStatus: ParkedType: Enhancement

Métricas do repositório

Stars
 (34.348 estrelas)
Métricas de merge de PR
 (Mesclagem média 3d 17h) (67 fundiu PRs em 30d)

Description

We currently start the jailer as the superuser (i.e. using sudo), and rely on the fact the process will deprivilege itself before exec-ing into Firecracker. It would be interesting to know if we can run the jailer using a more restricted set of capabilities instead of full superuser mode.

Guia do colaborador