From owner-freebsd-questions@freebsd.org Thu Dec 24 22:57:49 2020 Return-Path: Delivered-To: freebsd-questions@mailman.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.nyi.freebsd.org (Postfix) with ESMTP id 24C544D4175 for ; Thu, 24 Dec 2020 22:57:49 +0000 (UTC) (envelope-from 4250.82.1d4c70001826e7d.91669e647e4db32d5dbdda04b15c813d@email-od.com) Received: from s1-b0c6.socketlabs.email-od.com (s1-b0c6.socketlabs.email-od.com [142.0.176.198]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 4D257w0krcz3h1N for ; Thu, 24 Dec 2020 22:57:47 +0000 (UTC) (envelope-from 4250.82.1d4c70001826e7d.91669e647e4db32d5dbdda04b15c813d@email-od.com) DKIM-Signature: v=1; a=rsa-sha256; d=email-od.com;i=@email-od.com;s=dkim; c=relaxed/relaxed; q=dns/txt; t=1608850668; x=1611442668; h=content-transfer-encoding:content-type:mime-version:references:in-reply-to:message-id:subject:to:from:date:x-thread-info; bh=ARqpLbRKXPDY3Jjuje2CPleDFjX4xgboUUibMCoaYlo=; b=uZ9deb1pifOhSdzlpvyh+yODZr9Acomkj7Po4xUV/PSPan9v1MaAIej/Mrk5/Qp0mMsEgtwbWuRzEDSUo8TcT8V0AgtoyJpgUaANe1giVjSrTfynWKaPthwICnwFFJrqKHjP6Cru4ByzrAcZcYxcoFmzLxxYQtamPtiGGBcxsQ0= X-Thread-Info: NDI1MC45Mi4xZDRjNzAwMDE4MjZlN2QuZnJlZWJzZC1xdWVzdGlvbnM9ZnJlZWJzZC5vcmc= Received: from r2.us-east-1.aws.in.socketlabs.com (r2.us-east-1.aws.in.socketlabs.com [142.0.191.2]) by mxsg2.email-od.com with ESMTP(version=Tls12 cipher=Aes256 bits=256); Thu, 24 Dec 2020 17:57:45 -0500 Received: from smtp.lan.sohara.org (EMTPY [185.202.17.215]) by r2.us-east-1.aws.in.socketlabs.com with ESMTP(version=Tls12 cipher=Aes256 bits=256); Thu, 24 Dec 2020 17:57:44 -0500 Received: from [192.168.63.1] (helo=steve.lan.sohara.org) by smtp.lan.sohara.org with smtp (Exim 4.94 (FreeBSD)) (envelope-from ) id 1ksZYF-0008Nh-N0 for freebsd-questions@freebsd.org; Thu, 24 Dec 2020 22:57:43 +0000 Date: Thu, 24 Dec 2020 22:57:43 +0000 From: Steve O'Hara-Smith To: freebsd-questions@freebsd.org Subject: Re: Network namespaces in FreeBSD Message-Id: <20201224225743.5fbea1299f1d76c4af877668@sohara.org> In-Reply-To: <5b36e28e-d546-665a-1e89-6fa2323502e7@antonovs.family> References: <20201223182227.da6c11d3604eb07bb4f18ce5@sohara.org> <2581038e-fa0f-231d-ae33-1b42d50c8600@antonovs.family> <25fbf315-7aec-853c-cf69-a805805bd06e@antonovs.family> <9a80d70b-3f37-09ac-825f-c87e2c3e4925@qeng-ho.org> <5d38e65e-98e2-4c27-7ccb-37be93f868df@antonovs.family> <1687992626.3246491.1608839712067@mail.yahoo.com> <20201224201945.c8ce7c55c1ce68d729805a64@sohara.org> <5b36e28e-d546-665a-1e89-6fa2323502e7@antonovs.family> X-Mailer: Sylpheed 3.7.0 (GTK+ 2.24.32; amd64-portbld-freebsd12.1) X-Clacks-Overhead: "GNU Terry Pratchett" Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit X-Rspamd-Queue-Id: 4D257w0krcz3h1N X-Spamd-Bar: / Authentication-Results: mx1.freebsd.org; dkim=pass header.d=email-od.com header.s=dkim header.b=uZ9deb1p; dmarc=none; spf=pass (mx1.freebsd.org: domain of 4250.82.1d4c70001826e7d.91669e647e4db32d5dbdda04b15c813d@email-od.com designates 142.0.176.198 as permitted sender) smtp.mailfrom=4250.82.1d4c70001826e7d.91669e647e4db32d5dbdda04b15c813d@email-od.com X-Spamd-Result: default: False [-0.70 / 15.00]; RWL_MAILSPIKE_GOOD(0.00)[142.0.176.198:from]; MV_CASE(0.50)[]; R_SPF_ALLOW(-0.20)[+ip4:142.0.176.0/20]; TO_DN_NONE(0.00)[]; RCVD_COUNT_THREE(0.00)[4]; DKIM_TRACE(0.00)[email-od.com:+]; FORGED_SENDER(0.30)[steve@sohara.org,4250.82.1d4c70001826e7d.91669e647e4db32d5dbdda04b15c813d@email-od.com]; MIME_TRACE(0.00)[0:+]; RCVD_TLS_LAST(0.00)[]; ASN(0.00)[asn:7381, ipnet:142.0.176.0/22, country:US]; MID_RHS_MATCH_FROM(0.00)[]; FROM_NEQ_ENVFROM(0.00)[steve@sohara.org,4250.82.1d4c70001826e7d.91669e647e4db32d5dbdda04b15c813d@email-od.com]; ARC_NA(0.00)[]; NEURAL_HAM_MEDIUM(-1.00)[-1.000]; R_DKIM_ALLOW(-0.20)[email-od.com:s=dkim]; FROM_HAS_DN(0.00)[]; RBL_DBL_DONT_QUERY_IPS(0.00)[142.0.176.198:from]; TO_MATCH_ENVRCPT_ALL(0.00)[]; NEURAL_HAM_LONG(-1.00)[-1.000]; MIME_GOOD(-0.10)[text/plain]; DMARC_NA(0.00)[sohara.org]; RCPT_COUNT_ONE(0.00)[1]; SPAMHAUS_ZRD(0.00)[142.0.176.198:from:127.0.2.255]; NEURAL_SPAM_SHORT(1.00)[0.998]; RCVD_IN_DNSWL_NONE(0.00)[142.0.176.198:from]; MAILMAN_DEST(0.00)[freebsd-questions] X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 24 Dec 2020 22:57:49 -0000 On Thu, 24 Dec 2020 13:32:10 -0800 Ihor Antonov wrote: > On 12/24/20 12:19 PM, Steve O'Hara-Smith wrote: > > pkg jail nginx --jail webserver-3 --ip4addr ... > > > > and obtain a jail with just enough in it to run nginx (or > > whatever package you choose) and nothing else - by that I mean not a > > base system with the necessary packages but a system stripped of > > everything but the dependencies of the application - if the application > > doesn't need ls then ls isn't there. > > > Yes, that too. > > In linux world there is such a ting [1] and it is quite interesting, Not quite - AIUI those are manually constructed docker images, what I was thinking of was an extension to pkg to *automatically* create that minimal environment possibly with the aid of hints (as few as possible). -- Steve O'Hara-Smith