Hacker News new | ask | show | jobs
by mattacular 2012 days ago
Docker has a user namespacing feature which can be used to harden container images and also a newer way to run rootless altogether - https://docs.docker.com/engine/security/rootless/