3 ms·
Yes, pretty much, except for one detail: > That runs the codex OCI in a qemu microvm. AFAIU it's actually the other way around: krun spawns a libkrun-based (n
by codethief 2mo ago
Yes, pretty much, except for one detail:
> That runs the codex OCI in a qemu microvm.
AFAIU it's actually the other way around: krun spawns a libkrun-based (not QEMU-based) VM inside a crun container. Source: https://github.com/libkrun/libkrun/discussions/538#discussioncomment-15765542 https://github.com/libkrun/libkrun/discussions/538#discussio...
So with your solution you get the additional security benefit of containerizing the hypervisor on the host.
- figmert 2mo agoOnce you have a vm, the container provides next to no additional security benefits. It's just unnecessary overhead at that point.
- codethief 2mo agoThat's not correct. Virtio devices have different security properties and many of them expose the host system to considerable risks. Using containerization on the host is one way to limit the latter. See e.g. https://github.com/libkrun/libkrun/#security-model https://github.com/libkrun/libkrun/#security-model for more details.
- figmert 2mo agoWell, I stand corrected! Thanks for the link