Processes sandboxing
Foolproof Boundaries vs Unbounded Foolishness
- HN - For lightweight sandboxing on Linux you can use bubblewrap or firejail instead of Docker.
- TinyKVM: Fast sandbox that runs on top of Varnish
- Protecting your code from other people’s bugs / HN
Written on August 16, 2025, Last update on October 21, 2025
process
cgroup
sandbox
c++