Elektrine lite

← Feed

@spoofy@mastodon.com.pl

Post #3454692

2026-06-28 18:14 UTC

@grono@mastodon.com.pl well, I'm bigger fan of AppArmor instead of SELinux. Novell has done a great job, in fact, it pioneered practical implementations (e.g., changing the “hats” in mpm_prefork, etc.), which were subsequently adopted by Ubuntu and then merged into Debian. I would like to point out here that, for example, the Austrian Debian distribution Proxmox uses AppArmor for unprivileged containers (LXD and Incus as well). Ultimately, when it comes to Linux-based MAC/RBAC, AppArmor is, in my humble opinion, better - it offers greater control, is simpler to implement, and the ability to dynamically change HATs and quickly extend profiles is more convenient for me. As for OpenSUSE itself - I always see the same issue - whether to align more closely with Debian or Red Hat, and this is the source of disagreements over which standard to adopt.

Replies (1)

  • @grono@mastodon.com.pl 2026-06-28 20:37

    @spoofy@mastodon.com.pl well put! Glad to hear I'm not the only one finding apparmor better. I think SELinux makes sense for something like Android where the user is not expected to step outside it's userspace world. Anyway I was sad to see SUSE changing the default...

    Open ##3454690