Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

A default container seccomp profile will let you do quite a few things but you can use a different profile some json and limit to just a few system calls if you want such as doing IO on open FDs without the ability to open them. I think the runtime opens the FDs before the child process starts and are inherited.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: