Skip to content

Specifying security type of mount #11

@briantopping

Description

@briantopping

It's unclear how to specify a mount option such as sec=sys. When using a NFSv4 volume from a modern operating system, the negotiation will naturally take the highest level of security that is available.

Unfortunately, if that resolves to krb5, an arbitrary container is unlikely to have a ticket or the ability to acquire one. In that case, the contents of the volume will either be inaccessible or mapped to nobody. sec=sys is not ideal, but sufficient in a controlled security context.

Apologies if this is already addressed and I missed it in the documentation.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions