Skip to content

Conversation

@f100024
Copy link
Contributor

@f100024 f100024 commented Jul 30, 2025

This policy provides several security improvements over running shadowsocks as unconfined_service_t:

  • Principle of least privilege: Only grants necessary permissions
  • Network isolation: Controls which ports and connections are allowed
  • File system protection: Restricts file access to configuration and required system files
  • Process isolation: Runs in a dedicated SELinux domain
  • Audit trail: All access attempts are logged for security monitoring

@zonyitoo zonyitoo merged commit 5d491bc into shadowsocks:master Aug 6, 2025
17 checks passed
@zonyitoo
Copy link
Collaborator

zonyitoo commented Aug 6, 2025

In the security points of view, how is SELinux compared with Docker? I think the Docker or cgroup related solution could provide more restriction about isolation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants