Mailing List Archive
tlug.jp Mailing List tlug archive tlug Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: [tlug] Dealing with software with wide attack surface
- Date: Tue, 7 Sep 2021 19:19:24 +0200
- From: Jens John <lists@example.com>
- Subject: Re: [tlug] Dealing with software with wide attack surface
- References: <40c1ec0ee309801e6f04f6e05efc4eea@jp.sometwo.net> <m2a6kquzxa.fsf@sk.tsukuba.ac.jp> <YTVFbMDRmitm7zDi@fluxcoil.net> <YTdv/ph6V1kRzvMq@telephonic.cynic.net>
- User-agent: Mutt/2.1.2 (9a92dba0) (2021-08-24)
On Tue, Sep 07, 2021 at 10:58:22PM +0900, Curt J. Sampson wrote: > The core of containerisation, which you didn't mention, is simply > being able to configure processes to have different views of the > system. This is a pretty old idea (...) As far as Linux and the concept of "chroot() with more advanced unsharing of resources" goes, which arguably was present in many enterprise-class operating systems well before it arrived in Linux, VServer [1] deserves to be mentioned, which was one of the first attempts to make the concept working on Linux but got superceeded by other implementation directions. It still exists as franken-patches delivered by a single remaining active maintainer and a group of user enthusiasts who cling to the old ways. I mention this because one hosting company I did work at work some time switched to containers on Linux w/ VServer before containers were cool --- ending up having to support a server and service landscape based on pretty much unsupported code, having to patch and build kernels manually to keep it working instead of using distro upstream kernels, that is, supporting it for a fortune (in work). Debian keeping this legacy way too long in its repos was partly to blame for that. The current (relatively good) state of containers on Linux is a relief in many ways compared to "that". --- [1] http://linux-vserver.org/Welcome_to_Linux-VServer.org
- References:
- Re: [tlug] Dealing with software with wide attack surface
- From: furkan
- Re: [tlug] Dealing with software with wide attack surface
- From: Stephen J. Turnbull
- Re: [tlug] Dealing with software with wide attack surface
- From: Christian Horn
- Re: [tlug] Dealing with software with wide attack surface
- From: Curt J. Sampson
Home | Main Index | Thread Index
- Prev by Date: Re: [tlug] Dealing with software with wide attack surface
- Next by Date: Re: [tlug] Dealing with software with wide attack surface
- Previous by thread: Re: [tlug] Dealing with software with wide attack surface
- Next by thread: Re: [tlug] Dealing with software with wide attack surface
- Index(es):