Comment by figmert
20 hours ago
Docker containers use cgroups and namespaces etc (the usual kernel level isolation)
Docker sandboxes use microvms (i.e. hardware level isolation)
Bubblewrap uses the same technology as containers
I am unsure about seatbelt.
No comments yet
Contribute on Hacker News ↗