Skip to content

Sandbox Runtime Improvements #1720

@drew

Description

@drew

Improvements to the sandbox and supervisor machinery itself.

  • We should be able to sandbox any arbitrary container, not just containers specifically configured for OpenShell.
  • Drop elevated privileges such as CAP_SYS_ADMIN for running the supervisor.
  • Support different topologies such as running the supervisor simply as a network proxy.
  • Implement various isolation backends.
  • Configure Sandboxes with driver specific properties.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    Status
    Todo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions