Comment 3 for bug 1794550

Revision history for this message
Cédric Jeanneret (cjeanner) wrote :

Eeewwww...

That feature uses the fact we don't have SELinux separation.
Which is not really possible with podman, at least not as easily as docker which requires just a line in the daemon config. There might be something now with podman (not sure about the status), but I'm not sure we want to get that.

Would be good to discuss that matter. Disabling SELinux separation is a security issue (yeah, I know, already the case now) we probably don't want to push with a new container "engine".