All of lore.kernel.org
 help / color / mirror / Atom feed
* Containerized syslog
@ 2010-05-12 14:57 Jean-Philippe Menil
  0 siblings, 0 replies; 5+ messages in thread
From: Jean-Philippe Menil @ 2010-05-12 14:57 UTC (permalink / raw)
  To: containers-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA
  Cc: lxc-devel-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f

[-- Attachment #1: Type: text/plain, Size: 1098 bytes --]

Hi,

I'm playing with containers under debian (squeeze, 2.6.33.3) with the 
lxc tools.
I'm really happy about all the features (attach veth on bridge, filter 
with iptables inside the containers, etc ...), and i was thinking to 
replace some of our vservers (and maybe some of our kvm) with this solution.

But actually, i experiment a problem with the iptables logs:
i've iptables on the host to filter some container, basically a squid 
proxy. I've another container who act as router, and he has his own 
iptables inside.
All the log are deported to a dedicated syslog server.
It appear that, the iptables log of the host are also deported by the 
syslog container (proxy).

Some of our guest (container, vserver, etc ) are administer by other 
sys-admin, that should not have access to theses informations.

This point is blocking me today, before going into production with 
containers.

I've seen some patch made by Jean-Marc Pigeon about this problem,
but they have not been commited.

Is there any reason for that?
Can someone advice me to circumvent this problem?

Thanks a lot.

Regards.

[-- Attachment #2: jean-philippe_menil.vcf --]
[-- Type: text/x-vcard, Size: 458 bytes --]

begin:vcard
fn:Jean-Philippe Menil
n:Menil;Jean-Philippe
org;quoted-printable:Universit=C3=A9 de Nantes;IRTS - DSI
adr;quoted-printable:;;2, rue de la Houssini=C3=A8re;Nantes;Loire-Atlantique;44332;France
email;internet:jean-philippe.menil-zanJymNeSEOeCSforKHNpg@public.gmane.org
title;quoted-printable:Administrateur R=C3=A9seau
tel;work:02.51.12.53.92
tel;fax:02.51.12.58.60
x-mozilla-html:FALSE
url:http://www.criun.univ-nantes.fr/
version:2.1
end:vcard


[-- Attachment #3: Type: text/plain, Size: 206 bytes --]

_______________________________________________
Containers mailing list
Containers-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org
https://lists.linux-foundation.org/mailman/listinfo/containers

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2010-05-12 14:57 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
     [not found] <1265915683.19130.166.camel@Mercier.safe.ca>
     [not found] ` <1265915683.19130.166.camel-4BUXZ/Ty1v7iqR6jatDSCA@public.gmane.org>
2010-02-11 19:29   ` containerized syslog Serge E. Hallyn
     [not found]     ` <20100211192952.GA20191-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2010-02-13 15:58       ` Matt Helsley
     [not found]         ` <20100213155813.GU3714-52DBMbEzqgQ/wnmkkaCWp/UQ3DHhIser@public.gmane.org>
2010-02-13 16:03           ` Matt Helsley
2010-02-13 16:05           ` Serge E. Hallyn
2010-05-12 14:57 Containerized syslog Jean-Philippe Menil

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.