Hello,
is there a way to limit qvm-run-vm
inside a qube to specific service / .desktop
file, similar to qvm-run --service qubes.StartApp+my-service
in dom0
?
This at least would allow qube B to control the commands invoked from qube A, providing security benefits.
Background: I am evaluating different alternatives to have disposables in combination with minimal persistent state (in form of separate data qubes).