Slide 14
Slide 14 text
Linux 容器使⽤用的 Linux Kernel 功能
• Namespaces(mnt, pid, net, ipc, uts/hostname, user ids)
• cgroups(cpu, memory, disk, i/o - resource management)
• AppArmor, SELinux(security/access control)
• seccomp(computation isolation)
• chroot(file system isolation)