
Your Personal Cloud Platform with Sandstorm.io and Kenton Varda
Hanselminutes with Scott Hanselman
00:00
Sandstorm
Sandstorm uses the same Linux kernel features that Docker uses for containerization. The main things are attack surface reduction and designing a platform API that's actually sandboxable. On sandstorm, we drastically reduce the Linux API by using set comp Bpf to disable a lot of system calls. We don't mount Prox FS, we don't mountsys FS, those are huge interfaces that are not very well reviewed.
Play episode from 12:20
Transcript


