| ▲ | jononor a year ago | ||||||||||||||||
What is the best way? Or at least, a better way? | |||||||||||||||||
| ▲ | babush a year ago | parent | next [-] | ||||||||||||||||
I recall Shopify having a seccomp-based jail to run untrusted ruby code. But their use-case was very limited so they can get away with blocking almost every syscall. Other than that... VMs? The fact that people consider JS/WASM engines good security sandboxes is a bit scary tbf. | |||||||||||||||||
| |||||||||||||||||
| ▲ | kissgyorgy a year ago | parent | prev | next [-] | ||||||||||||||||
Landlock, cgroups on Linux | |||||||||||||||||
| ▲ | ehsanu1 a year ago | parent | prev [-] | ||||||||||||||||
gVisor | |||||||||||||||||