logoalt Hacker News

kaffekakayesterday at 8:30 PM0 repliesview on HN

I have used a separate user, but lately I have been using rootless podman containers instead for this reason. But I know too little about container escapes. So I am thinking about a combination.

Would a podman container run by a separate user provide any benefit over the two by themselves?