I just don't trust the Linux kernel to effectively isolate processes anymore. Don't care if you're using user namespaces, seccomp, etc. There will be a bug.
Time for Micro VMs, they're a stronger security boundary (not perfect, stronger)
Time for Micro VMs, they're a stronger security boundary (not perfect, stronger)
If your VM can't do anything, it's probably not very useful.
Doing things meaning reading / writing files, communicating between VMs, services, etc.