<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="FeedCreator 1.8" -->
<?xml-stylesheet href="http://wiki.infrazone.cc/lib/exe/css.php?s=feed" type="text/css"?>
<rdf:RDF
    xmlns="http://purl.org/rss/1.0/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
    xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel rdf:about="http://wiki.infrazone.cc/feed.php">
        <title>DokuWiki - bookstack:work:drivesec</title>
        <description></description>
        <link>http://wiki.infrazone.cc/</link>
        <image rdf:resource="http://wiki.infrazone.cc/lib/exe/fetch.php?media=wiki:dokuwiki.svg" />
       <dc:date>2026-04-19T17:05:00+00:00</dc:date>
        <items>
            <rdf:Seq>
                <rdf:li rdf:resource="http://wiki.infrazone.cc/doku.php?id=bookstack:work:drivesec:docker&amp;rev=1776112827&amp;do=diff"/>
                <rdf:li rdf:resource="http://wiki.infrazone.cc/doku.php?id=bookstack:work:drivesec:docker_ql1&amp;rev=1776112827&amp;do=diff"/>
                <rdf:li rdf:resource="http://wiki.infrazone.cc/doku.php?id=bookstack:work:drivesec:framework_architecture&amp;rev=1776112827&amp;do=diff"/>
                <rdf:li rdf:resource="http://wiki.infrazone.cc/doku.php?id=bookstack:work:drivesec:qa&amp;rev=1776112827&amp;do=diff"/>
                <rdf:li rdf:resource="http://wiki.infrazone.cc/doku.php?id=bookstack:work:drivesec:selinux&amp;rev=1776112827&amp;do=diff"/>
                <rdf:li rdf:resource="http://wiki.infrazone.cc/doku.php?id=bookstack:work:drivesec:todos&amp;rev=1776112827&amp;do=diff"/>
            </rdf:Seq>
        </items>
    </channel>
    <image rdf:about="http://wiki.infrazone.cc/lib/exe/fetch.php?media=wiki:dokuwiki.svg">
        <title>DokuWiki</title>
        <link>http://wiki.infrazone.cc/</link>
        <url>http://wiki.infrazone.cc/lib/exe/fetch.php?media=wiki:dokuwiki.svg</url>
    </image>
    <item rdf:about="http://wiki.infrazone.cc/doku.php?id=bookstack:work:drivesec:docker&amp;rev=1776112827&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2026-04-13T20:40:27+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>docker</title>
        <link>http://wiki.infrazone.cc/doku.php?id=bookstack:work:drivesec:docker&amp;rev=1776112827&amp;do=diff</link>
        <description>Docker

Useful resources

Building docker images 

How does the docker cache works 

Multi stages build use cases 

Buildkit Cach Mount</description>
    </item>
    <item rdf:about="http://wiki.infrazone.cc/doku.php?id=bookstack:work:drivesec:docker_ql1&amp;rev=1776112827&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2026-04-13T20:40:27+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>docker_ql1</title>
        <link>http://wiki.infrazone.cc/doku.php?id=bookstack:work:drivesec:docker_ql1&amp;rev=1776112827&amp;do=diff</link>
        <description>Docker

https://github.com/krallin/tini</description>
    </item>
    <item rdf:about="http://wiki.infrazone.cc/doku.php?id=bookstack:work:drivesec:framework_architecture&amp;rev=1776112827&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2026-04-13T20:40:27+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>framework_architecture</title>
        <link>http://wiki.infrazone.cc/doku.php?id=bookstack:work:drivesec:framework_architecture&amp;rev=1776112827&amp;do=diff</link>
        <description>Framework Architecture

Used languages

For modules that require the use of Docker (and therefore the use of Docker APIs), Go and Python can be considered. This is because they are the only two languages for which official SDKs are provided.

There are unofficial libraries available for other programming languages, but they rely on the fact that Docker provides REST APIs on a Unix socket.</description>
    </item>
    <item rdf:about="http://wiki.infrazone.cc/doku.php?id=bookstack:work:drivesec:qa&amp;rev=1776112827&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2026-04-13T20:40:27+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>qa</title>
        <link>http://wiki.infrazone.cc/doku.php?id=bookstack:work:drivesec:qa&amp;rev=1776112827&amp;do=diff</link>
        <description>Q/A

10/10/2023

SELinux: 

    D: Multi Level Security può essere una buona tecnologia per il nostro Use case?

    R: Multi Level Security è una modalità di utilizzo di SELinux in cui le possibilità di configurazione esplodono: ad ogni soggetto (processo) e ogni oggetto (file, socket,</description>
    </item>
    <item rdf:about="http://wiki.infrazone.cc/doku.php?id=bookstack:work:drivesec:selinux&amp;rev=1776112827&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2026-04-13T20:40:27+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>selinux</title>
        <link>http://wiki.infrazone.cc/doku.php?id=bookstack:work:drivesec:selinux&amp;rev=1776112827&amp;do=diff</link>
        <description>SELinux

Procfs

In order to protect the system against memory dumps, it is needed limit access to minimum as possible to /proc. This folder contains a pseudo-filesystem which provides which provides an interface to kernel data structures&lt;sup&gt;[1]&lt;/sup&gt;.

Doing some basic test, SELinux define a protection against non-owned processes. An user, even if escalated to root, cannot access to root processes, because of SELinux labels.</description>
    </item>
    <item rdf:about="http://wiki.infrazone.cc/doku.php?id=bookstack:work:drivesec:todos&amp;rev=1776112827&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2026-04-13T20:40:27+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>todos</title>
        <link>http://wiki.infrazone.cc/doku.php?id=bookstack:work:drivesec:todos&amp;rev=1776112827&amp;do=diff</link>
        <description>TODOS

* ☒ SELinux

	*  ☒ Multi Level Security
		*  ☒ Ram Security - Protect against memory dumps
		*  ☒ Test catalog / test execution: Understand if it is possible to parallelize the work in two context
		*  ☒ Analyze which language can run with docker / ECR / registry

	*  ☒ Download box configurations directly from Box instead of having local files</description>
    </item>
</rdf:RDF>
