Access host's systemd from firejail --overlay namespace

Clash Royale CLAN TAG#URR8PPP
up vote
0
down vote
favorite
Instead of initializing a whole discrete system, I want to run isolated programs and services within the same host. I can already achieve that with firejail --noprofile --overlay, but the problem is because it's a separate namespace, I can't reach systemd from within it and have it run services.
Is there anyway to partially allow access to systemd? I don't have security concerns, I only want to isolate the services like a container.
If the same is achievable with other container tech like LXC, systemd-nspawn, Docker, etc I'm all ears.
container firejail
add a comment |Â
up vote
0
down vote
favorite
Instead of initializing a whole discrete system, I want to run isolated programs and services within the same host. I can already achieve that with firejail --noprofile --overlay, but the problem is because it's a separate namespace, I can't reach systemd from within it and have it run services.
Is there anyway to partially allow access to systemd? I don't have security concerns, I only want to isolate the services like a container.
If the same is achievable with other container tech like LXC, systemd-nspawn, Docker, etc I'm all ears.
container firejail
add a comment |Â
up vote
0
down vote
favorite
up vote
0
down vote
favorite
Instead of initializing a whole discrete system, I want to run isolated programs and services within the same host. I can already achieve that with firejail --noprofile --overlay, but the problem is because it's a separate namespace, I can't reach systemd from within it and have it run services.
Is there anyway to partially allow access to systemd? I don't have security concerns, I only want to isolate the services like a container.
If the same is achievable with other container tech like LXC, systemd-nspawn, Docker, etc I'm all ears.
container firejail
Instead of initializing a whole discrete system, I want to run isolated programs and services within the same host. I can already achieve that with firejail --noprofile --overlay, but the problem is because it's a separate namespace, I can't reach systemd from within it and have it run services.
Is there anyway to partially allow access to systemd? I don't have security concerns, I only want to isolate the services like a container.
If the same is achievable with other container tech like LXC, systemd-nspawn, Docker, etc I'm all ears.
container firejail
edited May 1 at 5:59
asked Apr 29 at 12:38
Oxwivi
1,0762921
1,0762921
add a comment |Â
add a comment |Â
active
oldest
votes
active
oldest
votes
active
oldest
votes
active
oldest
votes
active
oldest
votes
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f440722%2faccess-hosts-systemd-from-firejail-overlay-namespace%23new-answer', 'question_page');
);
Post as a guest
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password