Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Seems pretty glib. Be more specific about what "can't" be done? The preceding argument was about the inadequacy of namespaced shared-kernel containers for workload isolation. But there are lots of ways to isolate workloads.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: