|
|
|
|
|
by csmpltn
1535 days ago
|
|
> "Exactly. containers are not secure sandboxes by default and if one is breached all those K8s networking ACLs are worthless." Your suggestion being? Putting a sandbox inside a sandbox? How many layers deep should this be, before being considered "secure"? |
|
Gvisor and firecracker are the most popular sandboxes for containerized workloads.