All of lore.kernel.org
 help / color / mirror / Atom feed
* Building a SECURE cointainer using Cgroups ?
@ 2008-10-13 17:03 Tanaka, Thomas
       [not found] ` <0A97A441BFADC74EA1E299A79C69DF9212D3F6C9E2-osO9UTpF0UQ64kNsxIetb7fspsVTdybXVpNB7YpNyf8@public.gmane.org>
  0 siblings, 1 reply; 9+ messages in thread
From: Tanaka, Thomas @ 2008-10-13 17:03 UTC (permalink / raw)
  To: containers-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org

Hello,



Is it possible to build a secure container by using cgroups? My goal is to achieve a file system namespace container that will limit the file system view given to a process similar to chroot does but of course has to be secure.



Thank you in advance for your attentions and help.



Regards,



Thomas

^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2008-10-14  8:53 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-10-13 17:03 Building a SECURE cointainer using Cgroups ? Tanaka, Thomas
     [not found] ` <0A97A441BFADC74EA1E299A79C69DF9212D3F6C9E2-osO9UTpF0UQ64kNsxIetb7fspsVTdybXVpNB7YpNyf8@public.gmane.org>
2008-10-13 17:54   ` Dave Hansen
2008-10-13 18:01     ` Tanaka, Thomas
     [not found]       ` <0A97A441BFADC74EA1E299A79C69DF9212D3F6CA1B-osO9UTpF0UQ64kNsxIetb7fspsVTdybXVpNB7YpNyf8@public.gmane.org>
2008-10-13 18:25         ` Dave Hansen
2008-10-13 19:29           ` Serge E. Hallyn
     [not found]             ` <20081013192921.GA10814-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2008-10-13 20:57               ` Tanaka, Thomas
     [not found]                 ` <0A97A441BFADC74EA1E299A79C69DF9212D3F6CA82-osO9UTpF0UQ64kNsxIetb7fspsVTdybXVpNB7YpNyf8@public.gmane.org>
2008-10-13 21:04                   ` Serge E. Hallyn
     [not found]                     ` <20081013210420.GA26529-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2008-10-13 21:13                       ` Tanaka, Thomas
2008-10-14  8:53               ` Daniel P. Berrange

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.