Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 1 Jun 2019 20:30:31 -0400
From:      David Mehler <dave.mehler@gmail.com>
To:        freebsd-questions <freebsd-questions@freebsd.org>
Subject:   to jail or not to jail
Message-ID:  <CAPORhP4pbfCC96PXOeErJgswX_2dh%2BmXcBb1TrH6F0f5oN-wDw@mail.gmail.com>

next in thread | raw e-mail | index | archive | help
Hello,

I've got a newly installed FreeBSD 12 vps. It's going to be running a
web server/php hosting multiple sites, with letsencrypt tls
certificates for each. It's also going to be running an email server,
postfix, dovecot, rspamd, mysql database backend, again with the same
letsencrypt tls certificates. Previously I've had all this on one
host.

What I'm wondering is if I should jail off these services, I've got a
zfs setup, still trying to wrap my head around that, and am wondering
should I run the database in one jail, the webserver/php in another
jail, and the email server in a third jail? If I do this how would I
get the tls certificates in to each jail, I'm looking for the maximum
automation.

Thanks.
Dave.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?CAPORhP4pbfCC96PXOeErJgswX_2dh%2BmXcBb1TrH6F0f5oN-wDw>