|
|
|
|
|
by gundy
4743 days ago
|
|
They are not really efficient. All they do is add an extra layer of security so you can encapsulate that specific process in a chroot with its own networking stack. Other than that the CPU is still fairshared and the memory still has the same limits as if you ran it without the container. It adds nothing but security. |
|