TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Sandboxing Code in the Era of Containers

25 pointsby joaojeronimoabout 10 years ago

1 comment

mirashiiabout 10 years ago
Generally, the common wisdom is still that Docker, lxc, and linux containers in general haven&#x27;t been audited and hardened enough to use for multi-tenant isolation, so this seems like an odd choice. The article doesn&#x27;t talk at all about even doing some of the common hardening people might do in these circumstances (limit syscalls with seccomp, get rid of suid binaries, grsec, AppArmor).<p>I&#x27;d be extremely hesitant to trust the sandboxing here.
评论 #9273341 未加载