With my limited understanding of SELinux as a caveat, the use of SELinux with docker containers at the moment is limited to putting them all into a single context, which is good from the POV of container-to-host, but perhaps not good enough for container-to-container, going forward.
Power management, mobile and firmware developer on Linux. Security developer at Aurora. Ex-biologist. mjg59 on Twitter. Content here should not be interpreted as the opinion of my employer. Also on Mastodon.
Re: Because not enough people care about the kernel security features?
Date: 2015-11-06 03:56 pm (UTC)