[openstack-dev] [nova][cinder][neutron][security] Rootwrap on root-intensive nodes

Jeremy Stanley fungi at yuggoth.org
Wed Feb 4 16:33:35 UTC 2015


On 2015-02-04 13:40:29 +0200 (+0200), Duncan Thomas wrote:
> 4) Write a small daemon that runs as root, accepting commands over
> a unix domain socket or similar. Easier to audit, less code
> running as root.

http://git.openstack.org/cgit/openstack/oslo.rootwrap/tree/oslo_rootwrap/daemon.py

-- 
Jeremy Stanley



More information about the OpenStack-dev mailing list