Warning: Constant DISALLOW_FILE_EDIT already defined in /www/wwwroot/wp.rungobag.cn/wp-config.php on line 97

Warning: Constant DISALLOW_FILE_MODS already defined in /www/wwwroot/wp.rungobag.cn/wp-config.php on line 98
Show HN: Nucleus – A security-hardened, Nix-native container runtime – RUNGO RSS

Show HN: Nucleus – A security-hardened, Nix-native container runtime

作者:

Hi HN, I’ve been building Nucleus, a lightweight Linux container runtime focused on two workloads: ephemeral AI-agent sandboxes and declarative NixOS services. It’s a single Rust binary, no daemon.It is not a Docker replacement and not a strict subset of Docker either. I dropped the entire image-and-distribution half (no Dockerfile, no layers, no registry, no pull/push, no persistent storage layer) in exchange for going deeper on isolation and reproducibility. The rootfs is either a directory co…

查看原文 →


来源:Hacker News · RSS 采集

评论

发表回复

您的邮箱地址不会被公开。 必填项已用 * 标注