Y
Hacker News
new
|
ask
|
show
|
jobs
by
eecc
1948 days ago
You mean cgroups, or zones don’t you? Docker (was, last time I heard) a security disaster, not generating robust layer hashes, lacking user isolation, and plenty just running as root...
1 comments
giantrobot
1948 days ago
There's more to containers on Linux than just Docker.
link
ampdepolymerase
1948 days ago
To be fair you need to go to the hypervisor level (like Firecracker) to get any decent level of sandboxing.
link