Hacker News new | past | comments | ask | show | jobs | submit login

I always run my containers in a jail which I run in a zone which is running in a VM just in case.



I appreciate the humor but having an ability to run containers in a zone gives you very good isolation without overhead of a VM.


And never connect it to the internet, ever. Island is best land.


All behind NAT to make it securr




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: