LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Containers
User Name
Password
Linux - Containers This forum is for the discussion of all topics relating to Linux containers. Docker, LXC, LXD, runC, containerd, CoreOS, Kubernetes, Mesos, rkt, and all other Linux container platforms are welcome.

Notices


Reply
  Search this Thread
Old 09-15-2018, 03:27 PM   #1
taumeister
Member
 
Registered: Nov 2017
Location: Germany / Bonn
Distribution: Deepin Linux, Debian
Posts: 65

Rep: Reputation: 1
Is a firewall needed in an LXD Containier e.g Apache/Owncloud


Hi
I have created a Ubuntu LXD host under a Hyper-V server with some containers running in bridged mode.

1. HAProxy SSL
2. Owncloud
3. Wordpress
4. Kopano Mail System...etc.

What about the security of LXD containers?
Some say that a container of this kind should be treated like a normal operating system and the same security measures should be taken accordingly.
https://discuss.linuxcontainers.org/...tices-help/352
Normally I would then use at least a combination of 'iptables' and 'fail2ban'.
Others think that the isolation by the containers in combination with AppArmor and the reduction of the root account, bring enough security?

I honestly can't imagine it right. Can a container like the SSL proxy be hijacked in the same way just like a normal host, and does it need to be secured by e.g. ' iptabels'?

What are your security concepts in this area?

Last edited by taumeister; 09-17-2018 at 03:43 AM.
 
Old 09-17-2018, 01:47 AM   #2
pan64
LQ Addict
 
Registered: Mar 2012
Location: Hungary
Distribution: debian/ubuntu/suse ...
Posts: 22,039

Rep: Reputation: 7347Reputation: 7347Reputation: 7347Reputation: 7347Reputation: 7347Reputation: 7347Reputation: 7347Reputation: 7347Reputation: 7347Reputation: 7347Reputation: 7347
I think you mixed two different things: containers are isolated from each other and the host. But they work (more or less) as a VM and if you allow external access they will need the same protection as any other OS.
 
1 members found this post helpful.
Old 09-17-2018, 03:40 AM   #3
taumeister
Member
 
Registered: Nov 2017
Location: Germany / Bonn
Distribution: Deepin Linux, Debian
Posts: 65

Original Poster
Rep: Reputation: 1
Hello and thank you very much for your answer.
No, I'm not mixing anything here and I'm well aware of the difference.
And containers are almost like virtual machines but not complete.
They are much more isolated and the permissions within them are greatly reduced.
Normal containers are not privileged either.

But at the end of the day I came to a similar conclusion and limited all containers via iptables to the ports used as well as secured them with fail2ban - at least the two web servers.
Additionally I will read the BSI pages about basic protection and isolation of LXD environments.
Thanks
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] No permission to access owncloud with apache vincix Linux - Newbie 1 06-12-2016 01:08 PM
LXer: ownCloud Community Comes Up Big Delivering ownCloud 7 Community Edition LXer Syndicated Linux News 0 08-05-2014 06:30 PM
Move owncloud 4 to owncloud 5 to a different server the_bigbalu Linux - Server 2 05-28-2013 01:31 AM
LXer: ownCloud Inc. and the ownCloud community LXer Syndicated Linux News 0 12-16-2011 11:50 AM
Centos Firewall...needed if already behind a firewall? JohnRock Linux - Networking 7 05-22-2009 02:49 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Containers

All times are GMT -5. The time now is 09:53 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration