In reply to @dcuthbert

Daniel Cuthbert

@dcuthbert · Twitter ·

Untrusted workloads now run inside a layered, fail-closed sandbox that combines Linux namespaces, Landlock, seccomp-BPF, filesystem isolation, controlled network egress, environment sanitisation, and resource limits.