|
|
Subscribe / Log in / New account

Introducing Fedora CoreOS

Introducing Fedora CoreOS

Posted Jul 25, 2019 23:43 UTC (Thu) by rahulsundaram (subscriber, #21946)
In reply to: Introducing Fedora CoreOS by kjp
Parent article: Introducing Fedora CoreOS

SELinux is part of the upstream Linux kernel and widely used not just in the Red Hat family of Linux distributions but also by millions of phones through Android. It makes no sense to invest heavily on a technology and just let it die. For a very targeted system like Fedora CoreOS where everything is designed to run on containers, SELinux works way better and you never see it compared to regular Linux servers where you can run arbitrary applications in a variety of ways that are difficult to secure well

Virtualization is not a way to secure containers. I would recommend watching https://www.youtube.com/watch?v=a9lE9Urr6AQ on this topic. Firecracker is an interesting approach that uses KVM and is pitched as sort of in between alternative compared to containers and full VMS. Some of these approaches could be layered with SELinux but they don't seem to be playing in the same level.


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds