logoalt Hacker News

throwaway6734today at 2:13 AM1 replyview on HN

https://docs.docker.com/ai/sandboxes/ Any idea on how that compares to this docker feature in development?


Replies

figmerttoday at 3:43 AM

Docker containers use cgroups and namespaces etc (the usual kernel level isolation)

Docker sandboxes use microvms (i.e. hardware level isolation)

Bubblewrap uses the same technology as containers

I am unsure about seatbelt.