Luca, the creator of Distrobox, has created a great guide on how to use libvirt, qemu etc. in a Distrobox Container and then connect that to your client in another container using ssh
As far as I understood this has many benefits. If the containers are adapted to have the right filesystem permissions and all, they should be pretty tight. I imagine only /var/lib/libvirt and ssh, thats it. The client, for example virt-manager could be on your host OS or even also in a container. I tried this and it works great!
And the tor bridge would sit in another container, tight apart from the tor traffic, but no filesystem permissions at all.
The current guide is not hardened in that way, its simply "make this run on an immutable System without layering anything". And its great! But I think this also has greeeat potential for a really secure Qubes-like OS, but not using virtualization like crazy, but well isolated containers.
What do you think?
Luca, the creator of Distrobox, has created a great guide on how to use libvirt, qemu etc. in a Distrobox Container and then connect that to your client in another container using ssh
As far as I understood this has many benefits. If the containers are adapted to have the right filesystem permissions and all, they should be pretty tight. I imagine only /var/lib/libvirt and ssh, thats it. The client, for example virt-manager could be on your host OS or even also in a container. I tried this and it works great!
And the tor bridge would sit in another container, tight apart from the tor traffic, but no filesystem permissions at all.
The current guide is not hardened in that way, its simply "make this run on an immutable System without layering anything". And its great! But I think this also has greeeat potential for a really secure Qubes-like OS, but not using virtualization like crazy, but well isolated containers.
What do you think?