Enable security.nesting
by default for unprivileged containers and modern enough images
#13631
Labels
Maybe
Undecided whether in scope for the project
I believe we have no choice and should set
security.nesting=true
(unprivileged case only) for modern enough images (e.g. starting from Oracular [1]).This depends on a systemd version, not really a distro-specific thing.
For privileged containers, problem even more serious [2] as these days Noble doesn't work in a privileged container. And only works with nesting enabled which makes a container escapable.
See also:
[1] #12698
[2] #12967
The text was updated successfully, but these errors were encountered: