TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Nsjail – A light-weight process isolation tool for Linux

87 pointsby LaFolleover 7 years ago

7 comments

jeblairover 7 years ago
This seems very similar to Bubblewrap: <a href="https:&#x2F;&#x2F;github.com&#x2F;projectatomic&#x2F;bubblewrap" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;projectatomic&#x2F;bubblewrap</a>
评论 #15480857 未加载
woahhvickyover 7 years ago
How does this compare to firejail?
评论 #15478977 未加载
Bromsklossover 7 years ago
Is this what I should use if I want to intercept filesystem calls (and rewrite them, or generate on the fly the file that is about to be accessed)? Something else I should look into for this purpose?
评论 #15479561 未加载
评论 #15479554 未加载
thereinover 7 years ago
Is there a minimum required kernel version? How does it compare to proot?<p>We use proot in our build pipeline and it would be interesting to look into alternatives.
评论 #15479772 未加载
评论 #15479997 未加载
TheDongover 7 years ago
This seems to be almost exactly like systemd-nspawn other than the ability to write seccomp policies in kafel.<p>Are there any other notable differences?
评论 #15482752 未加载
_Marak_over 7 years ago
I&#x27;ve been using nsjail in production with good success lately. It&#x27;s a solid tool.<p>Thank you authors! Really appreciate your work on this project.
andystantonover 7 years ago
I have become conditioned by seeing so many Javascript frameworks reach the front page over the years that I parsed this as &#x27;JsNail&#x27; on first glance.