Remix.run Logo
treelover 7 hours ago

Interesting choice to use native Apple Containers over Docker.

I assume this is to keep the footprint minimal on a Mac Mini without the overhead of the Docker VM, but does this limit the agent's ability to run standard Linux tooling? Or are you relying on the AI to just figure out the BSD/macOS equivalents of standard commands?

ohyoutravel 6 hours ago | parent | next [-]

[flagged]

reassess_blind 5 hours ago | parent [-]

What makes you think it's an AI comment?

yomismoaqui 4 hours ago | parent [-]

Maybe what you are responding to is the AI comment? Or am I?

cadamsdotcom 5 hours ago | parent | prev | next [-]

If only there were some way to answer your own question. Maybe with some kind of engine that searches.

selkin 3 hours ago | parent | prev [-]

Not sure if it's intended, but Apple Container is a microvm, providing mich better isolation than containers (while retaining the familiar interface)

TheDong 12 minutes ago | parent [-]

"much better isolation than containers"

If you've got an exploit for docker / linux containers, please share it with the class.

What I'm saying is that in practice, containers and VMs have both been quite secure.

Also, you can configure docker to run microvms too https://github.com/firecracker-microvm/firecracker-container...