• Dran@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    15 days ago

    There are security performance and capability concerns with that approach, apparmor on the first layer lxc probably being the most annoying.

    If you want to isolate your docker sandbox from your main host, you should use a vm not a container.

    • wildbus8979@sh.itjust.works
      link
      fedilink
      arrow-up
      0
      ·
      edit-2
      15 days ago

      OP’s already running LXC on the host, so… Namespaces are namespaces…

      I don’t see what performance issues there would be with that.