lockc
lockc copied to clipboard
Use BPF LSM attached to cgroups
https://lore.kernel.org/bpf/[email protected]/
There is a kernel patchset which allows to attach BPF LSM programs to cgroups.
If I understand it correctly, that would allow us to get rid of "container monitoring" logic.