Hanselminutes with Scott Hanselman cover image

Your Personal Cloud Platform with Sandstorm.io and Kenton Varda

Hanselminutes with Scott Hanselman

00:00

Sandstorm

Sandstorm uses the same Linux kernel features that Docker uses for containerization. The main things are attack surface reduction and designing a platform API that's actually sandboxable. On sandstorm, we drastically reduce the Linux API by using set comp Bpf to disable a lot of system calls. We don't mount Prox FS, we don't mountsys FS, those are huge interfaces that are not very well reviewed.

Play episode from 12:20
Transcript

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app