logoalt Hacker News

LeBittoday at 10:01 AM1 replyview on HN

What if you use tools like bubblewrap or nono inside the container?

Say I want to use pi inside a container. If I wrap pi within a bubblewrap or within nono, how is that less secure than using a vm?

Also, I think most people run containers inside VMs anyway and not directly on their hosts (on Mac and windows you have to use a vm anyway).


Replies

akdev1ltoday at 12:21 PM

bubble wrap is just doing the same cgroups work

show 1 reply