onedr0p / home-ops

Wife approved HomeOps driven by Kubernetes and GitOps using Flux

Home Page:https://onedr0p.github.io/home-ops/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Rollout changes to apps to increase security

onedr0p opened this issue · comments

Set better security contexts on all apps.

The only apps that I cannot handle right now are:

  • frigate - Blocker: USB Device
  • lldap #6668
  • rtlamr2mqtt - Blocker: USB Device
  • zwave-js-ui - Blocker: USB Device

I tried with smarter-device-manager to make apps that require USB devices to work but some apps just need root or elevated perms. affffce

  • frigate: s6 infested
  • rtlamr2mqtt: rtl_tcp needs some CAPS (which I did not figure out) set
  • zwave-js-ui: worked fine