Hacker News new | ask | show | jobs
by progval 15 days ago
Successful sudo from a cgroup still makes you root on the machine. What you want for this is user namespaces, not (just) cgroups.
1 comments

yes, you would setup namespace and unshare it once mounted to isolate the sandbox so root only sees the sandbox / and not your /