4 comments

  • setheron54 minutes ago
    I have written <a href="https:&#x2F;&#x2F;fzakaria.com&#x2F;2020&#x2F;05&#x2F;31&#x2F;containers-from-first-principles" rel="nofollow">https:&#x2F;&#x2F;fzakaria.com&#x2F;2020&#x2F;05&#x2F;31&#x2F;containers-from-first-princi...</a> a while ago in similar vein.
  • js21 hour ago
    (2016). Previous submissions w&#x2F;comments:<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=30623372">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=30623372</a> (250 points | March 10, 2022 | 27 comments)<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=22232705">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=22232705</a> (267 points | Feb 4, 2020 | 29 comments)<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=15608435">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=15608435</a> (440 points | Nov 2, 2017 | 53 comments)
  • ranger_danger1 hour ago
    &gt; I wanted specifically to find a minimal set of restrictions to run untrusted code.<p>I don&#x27;t think we should consider containers to be a security boundary. Even full VMs can be escaped, and have been, many times.<p>The fact that this is possible in the first place makes me think we need a much better approach.
    • chubot56 minutes ago
      As far as I know, Firecracker, gVisor, and Kata Containers are the solution here. They use VM primitives (x64_64 and ARM64 extensions) and have lighter codebases<p><a href="https:&#x2F;&#x2F;firecracker-microvm.github.io&#x2F;" rel="nofollow">https:&#x2F;&#x2F;firecracker-microvm.github.io&#x2F;</a><p><a href="https:&#x2F;&#x2F;gvisor.dev&#x2F;" rel="nofollow">https:&#x2F;&#x2F;gvisor.dev&#x2F;</a><p><a href="https:&#x2F;&#x2F;katacontainers.io&#x2F;" rel="nofollow">https:&#x2F;&#x2F;katacontainers.io&#x2F;</a><p>But I don&#x27;t have any direct experience with any of them. I&#x27;d be curious what people who have built on top of them think<p>edit: OK it looks like Kata can use Firecracker, so as far as isolation, it&#x27;s either Firecracker or gVisor. And Firecracker is the VMM I mentioned, but gVisor is quite different -- it&#x27;s more like a user space kernel that emulates syscalls.
      • binsquare46 minutes ago
        I&#x27;m going to toss in smolvm as well because firecracker needs some expertise to make the box usable and secure.<p><a href="https:&#x2F;&#x2F;github.com&#x2F;smol-machines&#x2F;smolvm" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;smol-machines&#x2F;smolvm</a>
      • laurencerowe47 minutes ago
        As I understand it Kata supports multiple VMM backends, Firecracker, QEmu, Cloud Hypervisor, and their own Dragonball. Except QEmu, I believe those are all built on crates in the rust-vmm ecosystem, each making slightly different tradeoffs.
    • raesene915 minutes ago
      I definitely wouldn&#x27;t trust standard Linux style containers that expose a shared Linux kernel at the moment, there&#x27;s been far too many LPE and container breakout vulnerabilities this year. It&#x27;s possible that in future if the kernel gets a lot more hardened, that could change but things like Firecracker are a better bet from a security standpoint.
  • tankiya1 hour ago
    [flagged]