Hacker News new | ask | show | jobs
by exabrial 9 days ago
Handy for sure!

In production though, I've moved completely to systemd isolation of apps, rather than Docker-like containers; essentially blackboxes and present a supply chain threat. There's also a DRY principle here. Verification of a host presents a much smaller surface area.

1 comments

> moved completely to systemd isolation

On MacOS?

Negative:

> In Production