Hacker News new | ask | show | jobs
by blueflow 1162 days ago
Containers do isolation in userspace, its a pure software thing. Its not doing any kind of hardware isolation nor is it able to.
1 comments

Don’t they use cgroups? It’s software but the kernel helps.