Hacker News new | ask | show | jobs
by eecc 1948 days ago
You mean cgroups, or zones don’t you? Docker (was, last time I heard) a security disaster, not generating robust layer hashes, lacking user isolation, and plenty just running as root...
1 comments

There's more to containers on Linux than just Docker.
To be fair you need to go to the hypervisor level (like Firecracker) to get any decent level of sandboxing.