3 ms·
Outside of VM usage, the answer seems to be (on top of containerization and selinux) writing a tight seccomp filter. Gleaned from https://github.com/containers
by its-summertime 8mo ago
Outside of VM usage, the answer seems to be (on top of containerization and selinux) writing a tight seccomp filter.
Gleaned from https://github.com/containers/bubblewrap/blob/0c408e156b12ddc9097b06ce0a7bdab7085a9af2/README.md#system-security https://github.com/containers/bubblewrap/blob/0c408e156b12dd... and https://github.com/containers/bubblewrap/tree/0c408e156b12ddc9097b06ce0a7bdab7085a9af2/demos https://github.com/containers/bubblewrap/tree/0c408e156b12dd...