3 ms·
This is the way things should be done by any competent developer. Generally a VM jail is preferable - firecracker or cloud-hypervisor(virtiofs & gpu passthroug
by rogers18445 4y ago
This is the way things should be done by any competent developer.
Generally a VM jail is preferable - firecracker or cloud-hypervisor(virtiofs & gpu passthrough) recommended.
A proper namespace jail (eg. bwrap) is sufficient for 99.9% of cases. To break out of a properly configured namespace jail you would need to sacrifice a 0day.
- codedokode 4y agoIt looks like totally overengineered solution to me. The CPU already has a protected mode which doesn't allow the program to access any files directly. Why do you need to run a VM which by the way is run from the kernel (privileged mode) in Linux? Why cannot you run untrusted programs in protected mode?
- rogers18445 4y agoWith containers the entire surface area of the kernel is available to attack (syscalls). With a VM the surface is restricted to the VMM and KVM. This is an oversimplification, there may be other protocols that are passed through or utilized, they would add to the surface.