4 ms·
I haven't been looking at systemd-nspawn for some time, but judging from its man page: - ability to use config files (in nsjail in protobuf format) - 3 operat
by jagger11 9y ago
I haven't been looking at systemd-nspawn for some time, but judging from its man page:
- ability to use config files (in nsjail in protobuf format)
- 3 operational modes: one of them allows to listen on a TCP port and run processes on-demand (inetd-style)
- support for cgroups (pid and mem limiting), here rlimits are not enough
- more expressive seccomp-bpf rules
- TheDong 9y ago> ability to use config files systemd-nspawn supports ".nspawn" files (see --settings=true mode) > socket activation systemd can start up an nspawn thing in reaction to a systemd socket-activation request I think? > cgroups I guess for that you'd use 'systemd-run --scope -p MemoryLimit=10M -p CPUShares=100 -- systemd-nspawn ...' > more expressive seccomp-bpf rules Absolutely!