[flagged]
depending on use cases but its enough for most and way simpler to operate and maintain.
If you need stronger isolation, the other replies in this thread mention (gVisor on k8s) Depends on your threat model and how much infra complexity you want to manage.
Of course, it's impossible to know for sure what was LLM processed or not, but some (not all!) of your posts are getting classified that way.
You obviously have good points to make and are certainly welcome here! but if you'd please write text by hand which you plan to post to HN itself, we'd appreciate it. The community feels strongly about this right now.