基于Rust-vmm实现Kubernetes运行时We Have Done 1. Hardware Isolation 2. Security Tools - SELinux, Seccomp, AppArmor, Capabilities, Cgroup 3. Intrusion Detection - Monitor suspicious read/write to host files. For example, container Software Bullet Point Rule-based Sandbox RunC Needs to work with SELinux, AppArmor, Seccomp, cgroup VM-based Sandbox Kata-container BareMetal Only Heavy control logic Application kernel based Sandbox0 码力 | 27 页 | 34.17 MB | 1 年前3
共 1 条
- 1













