Hacker News new | past | comments | ask | show | jobs | submit login

If you're running a full docker daemon, then you'll be running as a privileged container which is worse or about the same in terms of terms of poor security. Anyone's workload can compromise the host, and likely the cluster.

Rootless containers are a lot of work and do not support many scenarios that you're going to need.

MicroVMs are the same experience as GitHub, full system and Kernel, do what you will. Even launch a nested VM.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: