skinny.

Latest / Linux Server Admin with Fexingo: Sysadmin, Bash, and Server Engineering

How to Harden Your Linux Server with AppArmor Profiles

In this episode of Linux Server Admin, Lucas and Luna dive into AppArmor—the mandatory access control system that's simpler than SELinux but powerful enough to confine major services like Nginx, MySQL, and Apache. They walk through a real-world case: a misbehaving PHP script that tried to write to /etc/passwd on a production web server, and how an AppArmor profile blocked it instantly. Lucas explains the difference between complain mode and enforce mode, how to generate profiles with aa-genprof, and why you should never run a profile in complain mode in production without auditing the logs…

The skinny

The skinny isn't ready yet — notes appear once the transcript is processed.