[lxc-users] Overcommit and kernel isolation

Serge Hallyn serge.hallyn at ubuntu.com
Thu Oct 9 16:56:09 UTC 2014


Quoting Bertrand Paquet (bertrand.paquet at gmail.com):
> Ok. Thx you for information.
> 
> It's very very dangerous :(

You at a very minimum should be using apparmor, selinux, or user namespaces.
Preferably user namespaces and one of apparmor or selinux.

-serge


More information about the lxc-users mailing list