Skip to content

Conversation

@michaelw
Copy link

@michaelw michaelw commented Jun 4, 2021

This disables a few sysctls that do not apply in LXC and docker
environments, without affecting the rest.

This disables a few sysctls that do not apply in LXC and docker
environments, without affecting the rest.
@mcgege
Copy link
Member

mcgege commented Jun 6, 2021

@michaelw Well, for me it looks like you have changed the logic that way: If $enable_sysctl_config is true (which is the default) then the class os_hardening::sysctl is always applied, independend of the environment. That means that most of sysctl settings are set also in container environment, and only a few are skipped.

I don't think that's the way it should be ...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants