I planed to do exactly this, with podman instead of docker, volume support.
Like:
$ podman run -it --rm -v .:/workspace local-dev-ia /usr/bin/oc
Configured with a .env file. Hope to do it hopefully before the end of the week.
Like:
$ podman run -it --rm -v .:/workspace local-dev-ia /usr/bin/oc
Configured with a .env file. Hope to do it hopefully before the end of the week.
This is nowhere near "exactly this". Docker Sandboxes uses micro VMs, you just use regular containers which have completely different security properties.
This is not what the person I was responding to is doing, though.
As for differences between the krun OCI runtime and Docker Sandbox (which also uses libkrun), let's please continue the discussion here: https://news.ycombinator.com/item?id=49240662 .