TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Sandboxing Code in the Era of Containers

25 点作者 joaojeronimo大约 10 年前

1 comment

mirashii大约 10 年前
Generally, the common wisdom is still that Docker, lxc, and linux containers in general haven&#x27;t been audited and hardened enough to use for multi-tenant isolation, so this seems like an odd choice. The article doesn&#x27;t talk at all about even doing some of the common hardening people might do in these circumstances (limit syscalls with seccomp, get rid of suid binaries, grsec, AppArmor).<p>I&#x27;d be extremely hesitant to trust the sandboxing here.
评论 #9273341 未加载