Skip to content

SimuzoFS filesystem isolation

Give each hosting account its own secure filesystem view—without rewriting your panel stack.

How it works

A jail view for every account

SimuzoFS builds a per-user jail under the configured jail home, binds a shared skeleton for system paths, and mounts user-specific persistent data for sensitive files. Authentication paths use a PAM module to prepare the jail context; path restrictions help keep operations inside allowed views.

  • pam_simuzofs.so — jail setup on login
  • simuzofs-ld.so — path restriction preload
  • simuzofs-cmd / simuzofsD — jail command tooling and daemon
  • simuzofs-init / setup — environment and skeleton management
Simuzo Users page — enable SimuzoFS isolation per account
Operations

Built for day-2 management

Enable globally, apply per user, rebuild when needed, and validate with CLI tests.

Install / uninstall

Feature toggle installs components system-wide and tracks progress in Tasks.

Per-user enable

Create the user’s persistent volume and configuration; rebuild virtual hosts as needed.

Reinit

Full skeleton rebuild and config migration for recovery or major structure changes.

Panel confs

Panel-specific skel and mount profiles for Webuzo, cPanel, Plesk, DirectAdmin, InterWorx, and more.

Mail & cron aware

Designed to work with common hosting entry points—not only interactive SSH.

Docs & tests

Isolation test suites and CLI diagnostics help validate jails after changes.

Admin workflow

Enable isolation in minutes

1. Turn on SimuzoFS

Enable in Settings. The installer/background task prepares system components and services.

2. Enable users

From Users, enable isolation for accounts (or bulk select). Virtual hosts can be rebuilt as needed.

3. Verify

Confirm jail paths, PAM wiring, and run isolation tests for pilot accounts before wide rollout.

FAQ

Common questions

What does SimuzoFS protect against?

It reduces cross-tenant filesystem visibility and accidental or malicious access to system paths and other users’ data by presenting each account with an isolated jail view.

How do I enable it for users?

Enable SimuzoFS globally in Settings (install runs as a background task), then enable it per user from User Management or via CLI: simuzofs --enable --user=USERNAME.

Does it work with SSH, cron, and web?

Yes. SimuzoFS is designed around common hosting entry points—including interactive login, scheduled jobs, and panel-driven execution—not only a single shell workflow.

Ready to secure your hosting nodes?

Install Simuzo on your panel server, enable isolation and limits, and give users a safer multi-tenant environment.

Product news, security improvements, and release notes for hosting providers.