‹ BackHN Continuity

Thread

Show HN: Drop – A rootless Linux sandbox with gVisor support

193 points · 63 comments · mixedbit

  1. zenoprax · · focus · HN ↗
    Can you explain a bit more about the boundary between the environment and my system? Is it just giving read-only access to /usr/lib?

    I use an alias to launch a Podman container with opencode in $PWD. It is fully ephemeral aside from the directories I map to it (usually a couple configs). XDG_HOME is local to that working dir. My only frustration is that my image is too minimal but that can be resolved.

    1. mixedbit · · focus · HN ↗
      This table shows which dirs are exposed from your system: <a href="https:&#x2F;&#x2F;droprun.sh&#x2F;docs&#x2F;sandbox-overview&#x2F;#filesystem-layout" rel="nofollow">https:&#x2F;&#x2F;droprun.sh&#x2F;docs&#x2F;sandbox-overview&#x2F;#filesystem-layout

      Compared to your setup:

      * &#x2F;usr is from your host, so you don&#x27;t need to maintain a separate image to have programs that you already have installed.

      * username, hostname, your current directory and home dir paths are preserved in the sandbox (within a Podman container a home dir is &#x2F;root)

      * environment variables are easy to carry into the sandbox.

      * environments are explicit (`drop ls` lists them) and can be removed with `drop rm`, so you don&#x27;t need to track in which dirs you have started Podman if you want to cleanup XDG_HOME files.

      It is likely that your Podman wrapper also solves some of these or they are non-issues for your. If your setup works well, I wouldn&#x27;t switch to something different.

      1. zenoprax · · focus · HN ↗
        Thanks. I think it&#x27;s probably more complicated than I need at the moment but good to know it is an option down the road!
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.