Yunohost App Sandbox Architecture Using systemd-nspawn
An architecture note on how Yunohost uses systemd-nspawn, overlayfs, and cgroups to create secure, resource-limited app sandboxes with minimal host privileges.
ReadMeFeed / Community knowledge
Real questions. Useful conversations. Find the people who know your stack.
An architecture note on how Yunohost uses systemd-nspawn, overlayfs, and cgroups to create secure, resource-limited app sandboxes with minimal host privileges.