4 ms·
It's not really. Any shared resource between containers or the kernel itself is an attack surface. Both options have a very wide attack surface - the kernel a
by cakealert 1y ago
It's not really.
Any shared resource between containers or the kernel itself is an attack surface.
Both options have a very wide attack surface - the kernel api.
Nothing really beats virtualization in security, the surface shrinks to pretty much just the virtualization bits in the kernel and some user space bits in the VMM.