• [gentoo-user] Choosing the right profile for Gentoo LXC/Docker containe

    From whiteman808@21:1/5 to All on Sun Dec 8 13:50:02 2024
    Hey,

    I'm going to setup Gentoo binary package server for LXC and Docker
    containers that will be used on the production server.

    On the server I already have hardened profile, so the my question is
    whether using hardened profile on the containers will be beneficial in
    terms of security or if it is sufficient to leave normal default Gentoo
    profile default/linux/amd64/23.0/systemd.

    I'll use these containers both for testing locally development
    applications on my laptop before deploying them, and also on the
    production server.

    I use this server mainly for hosting my own personal stuff like PHP
    websites, mailing lists, Jabber server, Git repositories.

    I want these containers to be easily deployable on different
    environments, and portable so I should set in CFLAGS, CXXFLAGS etc. -O2
    -pipe, without -march=..., right?

    Thank you in advance for helpful answers,
    whiteman808.

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)