logoalt Hacker News

Linux containers in 500 lines of code (2016)

83 points • by mkornaukhov • today at 2:09 PM • 17 comments • view on HN

Comments

js2 • today at 5:48 PM

(2016). Previous submissions w/comments:

https://news.ycombinator.com/item?id=30623372 (250 points | March 10, 2022 | 27 comments)

https://news.ycombinator.com/item?id=22232705 (267 points | Feb 4, 2020 | 29 comments)

https://news.ycombinator.com/item?id=15608435 (440 points | Nov 2, 2017 | 53 comments)

smashed • today at 9:39 PM

Coincidentally I mis-prompted claude code the other day while working on a toy project and failed to specify the project should be built on top of docker and not "like docker".

It went on to waste all my tokens creating a specialized docker clone. Cool I guess.

abidinberkay • today at 8:00 PM

This was written in 2016. What would be different if you wrote it today? For example would cgroups v2 or newer seccomp features change that much?

➕ show 1 reply
setheron • today at 6:22 PM

I have written https://fzakaria.com/2020/05/31/containers-from-first-princi... a while ago in similar vein.

ranger_danger • today at 6:17 PM

> I wanted specifically to find a minimal set of restrictions to run untrusted code.

I don't think we should consider containers to be a security boundary. Even full VMs can be escaped, and have been, many times.

The fact that this is possible in the first place makes me think we need a much better approach.

➕ show 7 replies
tankiya • today at 6:13 PM

[flagged]