logoalt Hacker News

pplougtoday at 3:40 PM1 replyview on HN

Docker sandboxes uses a MicroVM as an additional isolation layer - its not just containers (as also mentioned in the nanoclaw post)


Replies

verdvermtoday at 5:06 PM

This still does not help with, you can call foo, but not bar. We have plenty of existing tooling for that too.