logoalt Hacker News

echoangletoday at 12:19 AM2 repliesview on HN

Is there any service that relies on Linux user separation or containers to separate different user accounts? I’m pretty sure you’re not supposed to do that and the proper way is to run different instances in virtual machines.


Replies

ndiddytoday at 12:42 PM

Basically every shared webhost that uses cPanel works like this. The security mechanism they use is called CageFS (https://cloudlinux.com/getting-started-with-cloudlinux-os/41...), which makes it so users can't see other users, but it's not like a VM or something.

LelouBiltoday at 2:23 AM

Right, you're not supposed to do that...