Looks interesting. How does this compare to a container?
Containers aren't a sandbox:
https://news.ycombinator.com/item?id=46405993
It uses Linux kernel namespaces instead of chroot (containers are just fancy Liunx chroot)
Containers aren't a sandbox:
https://news.ycombinator.com/item?id=46405993