[OmniOS-discuss] Ang: LX Zones question: Do you miss ipadm(1M)?

Joshua M. Clulow josh at sysmgr.org
Fri Mar 31 06:04:53 UTC 2017


On 30 March 2017 at 14:46, Bob Friesenhahn <bfriesen at simple.dallas.tx.us> wrote:
> Something I see is that with normal Solaris zones, one can provide root
> access to a relatively untrusted third-party since everything important can
> be locked-down.  This approach should currently not be used with LX Zones.

Why is that?  There shouldn't be any difference between a native zone
and an LX zone with respect to untrusted workloads.  The containment
model is the same in both cases.


Cheers.

-- 
Joshua M. Clulow
UNIX Admin/Developer
http://blog.sysmgr.org


More information about the OmniOS-discuss mailing list