Jessie Frazelle 5/20/2018

Containers, Security, and Echo Chambers

Read Original

The author, a former Docker security maintainer, addresses confusion around container sandboxing, particularly in response to projects like gVisor. They argue that existing Linux security features (Seccomp, AppArmor, SELinux, cgroups, capabilities) already provide strong, overlapping layers of isolation when properly configured, and critiques the marketing narrative that these are insufficient for arbitrary applications.

Containers, Security, and Echo Chambers

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser