IPE

FAQ

How does IPE relate to SELinux and AppArmor?

SELinux and AppArmor confine what a running process may access. IPE decides whether a file-backed executable operation is allowed based on the integrity properties of the file. They compose as stacked LSMs.

Can I run IPE in a container?

IPE is currently system-wide. Namespace support is on the roadmap.

Which kernel do I need?

6.12 or newer.

Where is the full technical documentation?

Admin Guide — policy syntax, securityfs interface, audit records, threat model, known limitations.

Design Documentation — architecture and implementation.

Why is the mascot a seal?

A seal is what you press onto a document to attest its origin and make tampering evident.