• 4 Posts
  • 561 Comments
Joined 2 years ago
cake
Cake day: August 11th, 2023

help-circle











  • Neat. Tbh the app you are securing being the one in charge makes this limited and not a replacement of SELINUX or containers, but it does add some neat features like dynamic controls based on runtime configs that have bit my butt before. So say you set a port or working dir during startup, now it can set landlock to that and the actual process running it will be limited. Very cool still.