Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Isolating Containers with ZFS and Linux Namespaces (klarasystems.com)
15 points by klarainc 11 months ago | hide | past | favorite | 1 comment


If someone is looking for an out of box solution: This works fine with incus (former LXD). https://linuxcontainers.org/incus/

Some things are not namespaced yet in the kernel - so running Kubernetes in a namespace is not possible due to some network module requirements that are missing. NFS is another issue. SELinux might also be impossible.

But it's perfectly fine for most everyday needs.

What's missing is something like blkio but there is work in the openzfs pull requests.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: