logoalt Hacker News

0x457 • yesterday at 5:02 PM • 3 replies • view on HN

I'm confused why VM + systemd-nspawn? From my understaing WSL 2 runs a single VM + something like systemd-nspawn per "linux installation", but it runs a VM because it needs linux kernel. Why not just do systemd-nspawn if you alread on linux?


Replies

pkulak • yesterday at 5:21 PM

Way better isolation, is my guess. Plus, you can use a different kernel this way.

I used to poo-poo when people said that containers aren't a _real_ security boundary, at least for personal stuff, and not a multi-tenant server. But I bet even mid-tier LLMs can break out of LXC/Docker/nspawn at this point.

➕ show 1 reply
bketelsen • yesterday at 5:08 PM

you could, and if that's your preference https://nspawn.org is just right.

➕ show 2 replies
delusional • yesterday at 5:03 PM

Claude told him to do it this way.

➕ show 1 reply