Setting the transit namespace at runtime
ju.orth at gmail.com
Fri Sep 7 21:06:16 CEST 2018
> I'd thought of this early on, but failed to come up with what seemed
> like an actually realistic use case for it.
How about creating Wireguard devices as a user that has no
privileges/capabilites in the init namespace?
$ unshare -r -U -m
$ mount --bind /proc/self/ns/net init-ns
$ unshare -n
$ wg set wg0 transit-net init-ns
More information about the WireGuard