[apparmor] Using apparmor to enforce the network port

Sherman Boyd sherman.boyd at armored.io
Thu Sep 15 05:22:22 UTC 2011


Hi,

I'd like to use apparmor to do some sandboxing for node.js apps.  We want to
control what files the app has, make sure the app can't access memory that
it shouldn't and make sure the app is running on a specified network port.

The filesystem stuff seems pretty straitforward.  I think the memory level
stuff is already taken care of right?  But I haven't been able to find any
thing on the network level restrictions.  Is this even something I can do
with apparmor?

BTW I tried dropping by the IRC channel ... is it defunct?


Best regards,


*Sherman Boyd*

Executor, Armored Infrastructure

   email: sherman.boyd at armored.io

    www: armored.io
toll free: +1 (855) 711-7337
      fax: +1 (855) 712-7337
  skype: sherman.boyd
 twitter: @shermanboyd <http://twitter.com/#!/shermanboyd>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.ubuntu.com/archives/apparmor/attachments/20110914/5c94503d/attachment.html>


More information about the AppArmor mailing list