logoalt Hacker News

orliesaurustoday at 4:06 PM0 repliesview on HN

So this seems to be useful to me, when you run drop run it starts a child process and places it into a Linux namespace...it gives the process a separate identity and limited privileges so itt can appear to be root inside the sandbox without being root on the host. It also gives it a separate view of the filesystem and all processes inside see their own process tree rather than all host processes. same for network connections.

BUT IT DOESNT WORK ON MAC OS :( bummer (it's Linux-specific)

Guess i'll test it on a VPS