Hacker News new | past | comments | ask | show | jobs | submit login

Docker is not using chroot and iptables aren’t the most important part of “creating the perception”. The primary tools are Linux namespaces and cgroups. For many purposes, these abstractions aren’t too leaky (and sometimes quite useful without Docker, too)



Hmm this may have been because of the version of docker I used.

Updated the content




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: