Skip to content

Sandbox Runtime Improvements #1720

Description

@drew

Improvements to the sandbox and supervisor machinery itself.

  • We should be able to sandbox any arbitrary container, not just containers specifically configured for OpenShell.
  • Drop elevated privileges such as CAP_SYS_ADMIN for running the supervisor.
  • Support different topologies such as running the supervisor simply as a network proxy.
  • Implement various isolation backends.
  • Configure Sandboxes with driver specific properties.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    Status
    Todo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions