logoalt Hacker News

tucnaktoday at 3:04 PM0 repliesview on HN

If you're not into rootless Docker, but still want to improve sandboxing capabilities, consider alternative runtimes such as runsc (also known as gVisor)

https://gvisor.dev/docs/