HN2new | past | comments | ask | show | jobs | submitlogin

Jails. Recently I have configured a dedicated server to run nginx + php-fpm in jail: an entire jail consists of two static executable files, a few config files, and a few logs. There's nothing to pwn there, even if there's unpatched stack vulnerability somewhere. Jails are a very impressive security feature of FreeBSD.


Do you know how they compare to Linux Containers?


They are similar.

My trepidation with LXC would be from a documentation POV... Jails are very much known quantities, while LXC is newer, not known for great docs, and thus is probably easier to screw up.

See this HN thread for more discussion:

https://hackernews.hn/item?id=4015172




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: