CRIU and SELinux - Adrian Reber, Red Hat Nov. 13, 2019

from The Linux Foundation·

CRIU and SELinux - Adrian Reber, Red Hat Forum 1 Speakers: Adrian Reber To implement container live migration with Checkpoint/Restore in Userspace (CRIU) for container runtimes which are using SELinux, CRIU needs to handle SELinux labeling correctly. This talk will describe what was necessary to be able to fully restore processes with all SELinux labels and how this is difficult when trying to live migrate containers. At the same time this talk wants to highlight that it is now possible to migrate processes or containers without losing SELinux state and information. This talk also tries to collect feedback if the …



CRIU and SELinux - Adrian Reber, Red Hat Forum 1 Speakers: Adrian Reber To implement container live migration with Checkpoint/Restore in Userspace (CRIU) for container runtimes which are using SELinux, CRIU needs to handle SELinux labeling correctly. This talk will describe what was necessary to be able to fully restore processes with all SELinux labels and how this is difficult when trying to live migrate containers. At the same time this talk wants to highlight that it is now possible to migrate processes or containers without losing SELinux state and information. This talk also tries to collect feedback if the current implementation in CRIU is missing important parts.