Skip to content
This repository has been archived by the owner on Dec 15, 2024. It is now read-only.

agent: sandbox filesystem on linux (usin go-landlock) #25

Merged
merged 3 commits into from
Jan 14, 2023
Merged

Conversation

shoenig
Copy link
Owner

@shoenig shoenig commented Jan 14, 2023

This PR uses shoenig/go-landlock to setup a filesystem sandbox for donutdns, when running on a capable Linux system. Enabled read-only permissions on Allow/Block/Suffix files, and system TLS certificates.

@shoenig shoenig merged commit 04e03dd into main Jan 14, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant