I'm interested to learn about their sandboxing. They allow a lot of user-submitted code to run server side. How do they sandbox this? What level of isolation do they use?
- If language-runtime patches, then there are escapes likely.
- If chroot, then there are escapes.
- If linux namespaces, then there are escapes.
- If ...
Which level did they go for?