It provides kernel isolation for running untrusted code which is a security boundary that traditional containers can't guarantee.
I'm engaged with a third party security penetration company for their review, and will be happy to share it publicly when it is available.
It provides kernel isolation for running untrusted code which is a security boundary that traditional containers can't guarantee.
I'm engaged with a third party security penetration company for their review, and will be happy to share it publicly when it is available.