Hacker News new | past | comments | ask | show | jobs | submit login

> In particular, if you need to replace not just glibc, but also a bunch of system libraries (pretty common case for complex apps), it's often easier to unshare(CLONE_NEWNS), followed by bind-mounting over new /lib64 and /usr/lib to override specific directories. This is much lighter than full-on containers

This is basically what Flatpak does.




is flatpak mainly designed for desktop gui? wish there are cli tools to help to develop non gui program with unshare


You can use bubblewrap, the sandbox Flatpak uses. However, the command lines will get pretty long.


Yeh, exclusively.

For non-gui the closest thing is Docker/Podman.




Consider applying for YC's W25 batch! Applications are open till Nov 12.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: