3 ms·
On Linux, namespaces and seccomp have minimal overhead. seccomp can filter syscalls directly, so if you just need to convert formats, you could load the library
by iczero 5y ago
On Linux, namespaces and seccomp have minimal overhead. seccomp can filter syscalls directly, so if you just need to convert formats, you could load the library in a helper process and drop privileges. Sure the helper process would require more resources, but it shouldn't take much. For more sophisticated isolation, Linux namespaces can be used.
Out of boredom, I started 400 containers with podman running only bash in Ubuntu. It used less than 1 GB of RAM in total. podman is likely overkill if you just want sandboxing, however.
I'm sure there are still tradeoffs to containerization but at least the overhead is minimal.