Hacker News new | ask | show | jobs
by fc417fc802 160 days ago
A VM is more robust as a security boundary than a container is. Still not as good as independent physical hardware but certainly worthwhile.
1 comments

We're not talking VM vs containers. We're talking VM vs no VM at all in base system.
I understand that. I'm saying that wrapping all the dev containers up inside a single VM serves to further protect the host system from the dev containers.