Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
CoolCold
10 months ago
|
parent
|
context
|
favorite
| on:
Coolify: Open-source and self-hostable Heroku / Ne...
I have much more peace of mind when it's not in chroot but even better inside systemd unit and all that ReadonlyPath and capabilities applied. In the ideal case network access beyond localhost and may be db is denied for greater safety
nine_k
10 months ago
[–]
Sounds quite a bit like a container!
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: