| ▲ | Hugsun 38 minutes ago | ||||||||||||||||
Docker containers use Linux kernel features to create an isolated environment, running on the same machine as docker is. This creates a virtual machine, with its own kernel, and runs the container in there. This gives stronger isolation and security guarantees. | |||||||||||||||||
| ▲ | eloisius 32 minutes ago | parent | next [-] | ||||||||||||||||
I have the same question as GP. Your answer helps a little but not really. I might be naive, but I was under the impression that malicious code escaping a docker image and running amok on my host system was not something I should be too worried about. Especially if I run docker in rootless mode. Is that wrong? For clarity I’m actually using podman, not Docker. | |||||||||||||||||
| |||||||||||||||||
| ▲ | sureglymop 19 minutes ago | parent | prev [-] | ||||||||||||||||
That depends on the runtime though. For example, libkrun lets you do this:
That starts/runs the OCI in a qemu microvm. | |||||||||||||||||