-
I recently settled for opensnitch which seems to be the optimal choice in class.
I don't have a clear idea what the state of the issue is. It seems firejail/apparmor have obscure docs, or they are not intended for average/sane users, maybe as the basis for more friendly wrappers. Flatpak/bubblewrap currently doesn't support Netns (so personally I use firejail to sandbox firefox, in a proxied netns). |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
From the looks of it opensnitch is a firewall application that does not actually provide the file system sandboxing.
It does in a sense that it can create a new network namespace for sandbox. However, it does not provide any tools to work with new namespace. You can use tools like |
Beta Was this translation helpful? Give feedback.
From the looks of it opensnitch is a firewall application that does not actually provide the file system sandboxing.
It does in a sense that it can create a new network namespace for sandbox. However, it does not provide any tools to work with new namespace. You can use tools like
slirp4netns
to create networking for the new namespace. Bubblejail has a service that can use slirp4netns to create separated networking in sandbox.