Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

1. Containers != Docker.

2. If all you need are resource limits, processes in cgroups work pretty well.

3. Networking adds complexity - avoid network namespaces if you can, and use use an abstraction layer so the application doesn't have to worry about things like wire formats, encryption, TCP connections, IP addresses, and port numbers.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: