[OmniOS-discuss] Ang: LX Zones question: Do you miss ipadm(1M)?
Joshua M. Clulow
josh at sysmgr.org
Fri Mar 31 06:04:53 UTC 2017
On 30 March 2017 at 14:46, Bob Friesenhahn <bfriesen at simple.dallas.tx.us> wrote:
> Something I see is that with normal Solaris zones, one can provide root
> access to a relatively untrusted third-party since everything important can
> be locked-down. This approach should currently not be used with LX Zones.
Why is that? There shouldn't be any difference between a native zone
and an LX zone with respect to untrusted workloads. The containment
model is the same in both cases.
Cheers.
--
Joshua M. Clulow
UNIX Admin/Developer
http://blog.sysmgr.org
More information about the OmniOS-discuss
mailing list