hanke@feddit.nu to linuxmemes@lemmy.worldEnglish · 15 days agoMy Self Hosting Journeyfeddit.nuexternal-linkmessage-square168fedilinkarrow-up11arrow-down10
arrow-up11arrow-down1external-linkMy Self Hosting Journeyfeddit.nuhanke@feddit.nu to linuxmemes@lemmy.worldEnglish · 15 days agomessage-square168fedilink
minus-squareDran@lemmy.worldlinkfedilinkarrow-up0·15 days agoThere are security performance and capability concerns with that approach, apparmor on the first layer lxc probably being the most annoying. If you want to isolate your docker sandbox from your main host, you should use a vm not a container.
minus-squarewildbus8979@sh.itjust.workslinkfedilinkarrow-up0·edit-215 days agoOP’s already running LXC on the host, so… Namespaces are namespaces… I don’t see what performance issues there would be with that.
There are security performance and capability concerns with that approach, apparmor on the first layer lxc probably being the most annoying.
If you want to isolate your docker sandbox from your main host, you should use a vm not a container.
OP’s already running LXC on the host, so… Namespaces are namespaces…
I don’t see what performance issues there would be with that.