lockc icon indicating copy to clipboard operation
lockc copied to clipboard

Use BPF LSM attached to cgroups

Open vadorovsky opened this issue 2 years ago • 0 comments

https://lore.kernel.org/bpf/[email protected]/

There is a kernel patchset which allows to attach BPF LSM programs to cgroups.

If I understand it correctly, that would allow us to get rid of "container monitoring" logic.

vadorovsky avatar Apr 06 '22 12:04 vadorovsky