I can imagine that using eBPF will be faster, but I never really imagined SElinux as slow myself. I guess it's because of all the files that need to be opened, and updating policy.
They probably mean for hyper scaling environments SElinux is slow to use, it is designed for traditional servers that don't change often.
It's interesting to see my old pal SElinux be replaced.
voxadam•1mo ago
etyp•1mo ago
(edited to not assume anything)
loeg•1mo ago
https://lpc.events/event/19/contributions/2159/
man8alexd•1mo ago