3 ms·
What is firecracker needed? Couldn’t this just run in a container directly? I understand some of the isolation concerns but a browser and container breakout is
by SomaticPirate 4mo ago
What is firecracker needed? Couldn’t this just run in a container directly? I understand some of the isolation concerns but a browser and container breakout is a billion dollar CVE, no?
- arianvanp 4mo agoIf you follow the kernel mailing list container breakout exploits are currently a weekly occurrence
- WhyNotHugo 4mo agoYou can take a snapshot of a microVM and roll back. I've never heard of this being done with containers.
- flaminHotSpeedo 4mo agoMost mature and/or security conscious providers don't consider containers to be a secure isolation boundary (with Microsoft being a notable exception, though it's unclear whether that's a failure of internal policy or incompetent enforcement of policy). Containers provide a much broader attack surface than VM's, and since they're not considered secure as an industry standard there's likely to be less resources put towards managing container escape CVE's than VM escape ones.
- y2244 4mo agoBut everyone is running containers on Kubernetes?