|
|
|
|
|
by otabdeveloper4
810 days ago
|
|
> Turns out that's exactly what containers are a packaging of! Well, no. When people say "containers", they always mean "Docker". And Docker also comes with a daemon with full root permissions and ridiculous security policies. (Like, for example, forcefully turning off your machine's firewall, #yolo. WTF!) P.S. I actually run systemd-nspawn in production, but I am probably the only person on earth to do so. |
|
Not really / not necessarily. https://github.com/opencontainers/runtime-spec