Hacker News new | ask | show | jobs
by Aldipower 13 days ago
Sandboxing in a container in Linux isn't hard, if you use lxd/incus which ships with Ubuntu/Debian.
1 comments

It all seems so simple at first. Just launch a container/vm with a base image of your dev environment, mount whatever you need, do your work, and then tear down. Maybe add some iptables rules for good measure. Easy peasy, something any moderately competent dev could do and even put in a quick shell script.

I started with that assumption, but there are a lot more gotchas and security issues than you'd think.