2 ms·
See Google's gvisor as an attempt at reducing the attack-surface of a container to make things more secure. I think the general advice is that a single contain
by maxmcd 3y ago
See Google's gvisor as an attempt at reducing the attack-surface of a container to make things more secure.
I think the general advice is that a single container can never be a robust security boundary because the OS surface area they involve is so large that the isolation layer is ripe for possible vulnerabilities. You also really have to avoid screwing up, there are lot of fiddly little security mistakes you can make when attempting to use a container to run untrusted code.
Typically you might use something like gvisor, or a VM. Systems where isolation is simpler to reason about and the attack surface is smaller.
In any case a single isolation boundary can have a vulnerability and my understanding is that more advanced systems typically involve multiple layers of isolation to sandbox untrusted code.