-
Notifications
You must be signed in to change notification settings - Fork 18
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Added information for Unbound running under chroot. #9
base: main
Are you sure you want to change the base?
Conversation
Hi @ar51an ! I did not check compiled locally version of Unbound, so my changes are only for Unbound installed from repository. Tested on Debian 12. And thank you for your work! Brilliant! |
https://manpages.debian.org/bookworm/unbound/unbound.conf.5.en.html#chroot: Quoted below from the last paragraph in the link:
Using default configuration in the distribution provided unbound pkg the configs in this guide work fine for log and socket paths. The compiled version of Unbound provided at unbound-redis is using the same default config for chroot. Majority of the people use the default config for chroot, the provided configs in this documentation made sure it should work for them. Anyone using a custom config has to make the appropriate changes not just in this scenario but in other cases as well to meet their specific requirement. You changed the chroot in your personal config from default to point to some dir. That is why you got the errors and has to give permission within apparmor. So you can either comment out the chroot line in your config to keep it default or make the apparmor change. What is the value of chroot in your unbound.conf? |
Hi! Debian 12. |
Hello,
|
I did not specify any chroot additionally, so this is the default behavior.
So this is the expected, |
|
Thanks for the update. Distro is setting the chroot dir somewhere outside the unbound build and config, most probably using the distro specific apparmor unbound config along with distro specific unbound-helper script. This dashboard and the unbound build setup is targeted at the compiled version of unbound. Compiled version works fine, I am using it. I will look into the distro based pkg of unbound and update the documentation at the appropriate place, linking to this pull request. |
Hi! |
@ar51an BTW, please setup a link to Buy me a Coffee or something else - I would donate for your work, and I believe others would like too |
No description provided.