Hacker News new | ask | show | jobs
by Nextgrid 1662 days ago
I'd still be concerned about kernel-level exploits in this case. I'd run every service in its own VM.
1 comments

There have been examples of people breaking out of VMs. My ultimate wish is to run everything on separate CPUs.