logoalt Hacker News

staticassertionyesterday at 11:13 PM1 replyview on HN

Nix wraps your process in namespaces and seccomp?


Replies

amusingimpala75yesterday at 11:33 PM

Not by default but tools like agent-sandbox.nix (bwrap, seccomp) or other nixpak (just bwrap but more popular) can provide those capabilities if you want in a fairly simple interface