darwin-containers / rund

OCI Container Runtime for Darwin
Apache License 2.0
432 stars 13 forks source link

Can this ever work without disabling SIP? #48

Closed jlsalmon closed 3 months ago

jlsalmon commented 3 months ago

Question in title. Security team aren't keen on disabling SIP on-premise, and also it can't be disabled on EC2 mac instances for example.

slonopotamus commented 3 months ago

Please, see #49. It might be possible to only requure disabling part of SIP. But until SIP prevents chroot call, disabling of that part is unavoidable.

jlsalmon commented 3 months ago

Sorry, I totally missed #49!