Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Notes on Running Containers with Bubblewrap (jvns.ca)
13 points by mfrw on June 28, 2022 | hide | past | favorite | 2 comments


Google's nsjail (https://github.com/google/nsjail) has a nice "inetd style" mode where it can launch a sandboxed process in response to a TCP connection for similar use cases to this (and is relatively quick to fire up).


Related material on Linux namespaces and "let's hand-roll our own docker":

https://blog.quarkslab.com/digging-into-linux-namespaces-par...




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: