Hacker News new | ask | show | jobs
by baggy_trough 1692 days ago
I do it inside a systemd nspawn container with a volatile file system, no network, minimal caps.