Methods for Administering Non-Global Immutable Zones
Administrators must explicitly configure access to immutable zones for administrative operations. More secure methods require authorization and depend on the MWAC policy in effect and on your mode of access. Secure methods use the trusted path. A simple, insecure method is to briefly make the zone mutable, make your changes, then reboot the zone as immutable.
-
Use the Trusted Path Domain – You must have access to a console and configure the console and users to access the Trusted Path Domain (TPD).
See Administering an Immutable Zone by Using the Trusted Path Domain.
Note:
Except for theflexible-configurationpolicy, the other three MWAC policies enforce thesafemode, where you can access and modify immutable files only. -
Make the entire zone temporarily writable – You must have access to a terminal window and be authorized to run the
zoneadmorzlogincommand.The
zoneadmmethod is useful for small, fast fixes. You boot the immutable zone as temporarily writable, make your changes, and reboot.The
zloginmethod is useful for editing protected files and updating packages. During thezloginsession, the zone is writable. This method cannot be used with console login.