Ask HW: Qubes OS alternative on LXD containers
qubes-os.org
qubes-os.org
What do you think about domain-based applications environments Linux distribution with UX similar to QubesOS but based on LXD? For instance, I need the following isolated domains: "work" with Ubuntu 20.04, "personal" with Archlinux, "secops" with KaliLinux for another employer, "media" with Ubuntu Studio. And my host OS just list applications inside domains in applications menu. For me it looks like Firefox Containers (https://addons.mozilla.org/en-US/firefox/addon/multi-account...) but for the applications.
If you do not trust code that runs as root, no container will save you.
This is the same problem I have wanting to run windows only games, and linux for pretty much anything else.
LXD does not provide security for that case.
(unprivileged containers do have some sort of security measure related to this by mapping the uid 0 inside the container to one that is not privileged outside the container. Tools that need root but make no privileged system calls can work inside an unprivileged container. Example: an installation script that wants to call a package manager to install shared libraries as dependencies might require root, but only for filesystem changes inside the container, so that works. Tools that require privileged access to the kernel will not work in unprivileged containers. - this is very simplified - containerization is process isolation and fine tuned privileges can reduce attack surface, but it should not be seen as a "one size fits all" solution for this particular case)
> pass X.org, Pulse Audio, Video devices, etc.
or that one
(this is harder to explain. Basically: X is not designed with security in mind: if you give a keylogger access to your X session it can log your keys. pulse audio means you are doing a deep dive, because if you map the isolated uid to the uid the pulseaudio server, containment is broken. It is possible by assuming the container is "on the network" but nontrivial and lets not talk about microphones or selective access. Finally passing through pcie devices that have direct memory access is the containment equivalent of paying for the bus and asking the process to be home for dinner.)
it is what at least I need, it works with SW I was required to install
> X is not designed with security in mind I considered risk, I understand that there are still vulnerabilities like some software can read keyboard input from other windows, but I take this risk. BTW, for full isolation I have seen that people start a new X.org session as well.
I realize having a closed-source Windows host can be a complete non-starter for many.
Bhyve on both works help you with such isolation, too.
I haven't used BSD, but I think jails are another solution in this space.
I used Qubes pretty heavily in school. The Windows 10 template was great for running STATA etc, and the way Qubes handles copy paste and file transfer were pretty great.
What I didnt like was having to restart qubes when updating software, and general complexity. I will go back to Qubes or something like it when I go back to school, though, as it is simpler to manage than multiboot or multiple computers.