Agent Vault should remain in close proximity to the sandboxed agent and not be exposed to the public internet; your standard network security controls apply.
The proxy itself currently implements a token-based auth scheme. Depending on your setup, you can have an orchestrator mint an ephemeral token to be passed to a sandboxed agent to authenticate with the proxy.
I can't help you with nvidia, but the Wayland thing can be worked around quite easily by running it under a nested compositor like cage. (This is how I run waydroid under Xorg)
I'm actually optimistic that this will improve. Google has apparently been working on replacing Chrome OS with android, which I have pretty strong opinions on but the upside is that if they want to go that route they're going to have to make Android officially work well on x86, at which point there's no reason that eg. LineageOS wouldn't be expected to follow suit.
Ya, I don't see any point in systemd adding this, but they did it already. Near as I can tell most of the laws just want to know a rough age category that can be provided by the OS. Seems to me an `echo "adult" > ~$USER/.config/law_compliance/age_category` would do the trick.
Anyone that cares can go check that file if they want an age category for some reason. Why does this need to be any more complicated?
If a parent really wanted, they could change the perms so only they could change that file.
I have no doubt that systemd will implement a place to store political party membership, religion, LGBT status, veteran or draft status, or ethnic group membership if a handful of governments start to require that information.
reply