The Stoned Hacker

Just passin’ through

  • 1 Post
  • 9 Comments
Joined 3 years ago
cake
Cake day: June 24th, 2023

help-circle
  • It’s not that difficult to get SELinux working with podman quadlets, especially if you run things rootless. I have a kerberized service account for each application I host and my quadlets are configured to run under those. I very rarely encounter applications that simoky can’t be run rootless but I usually can find an adequate alternative. I think right now the only thing that runs as root is one of the talk or collabora containers in my nextcloud stack. No selinux issues either.