6 ms·
> Container escapes can however be quite easy This is certainly true of docker-style container setups where the host kernel is shared directly with other tenan
by amonks 13d ago
> Container escapes can however be quite easy
This is certainly true of docker-style container setups where the host kernel is shared directly with other tenants, but it seems to me like a bold claim to make of gvisor as used by these systems.
- podocarp 13d agoFair enough, I kind of assumed their sandbox was just some generic container or bwrap thing everyone uses for agents nowadays