FAQ
How does IPE relate to SELinux and AppArmor?
SELinux and AppArmor confine what a running process may access. IPE decides whether a file-backed executable operation is allowed based on the integrity properties of the file. They compose as stacked LSMs.
Can I run IPE in a container?
IPE is currently system-wide. Namespace support is on the roadmap.
Which kernel do I need?
6.12 or newer.
Where is the full technical documentation?
Admin Guide — policy syntax, securityfs interface, audit records, threat model, known limitations.
Design Documentation — architecture and implementation.
Why is the mascot a seal?
A seal is what you press onto a document to attest its origin and make tampering evident.