Skip to main content

The Sandbox Stack - Paranoid Level Sandboxing #1

·44 words·1 min
DevOps devsecops sandboxing container-security podman oci landlock nono seccomp firewall nftables dns unbound cve grype video
Table of Contents

Summary
#

Learn how to sandbox untrusted software, from AI agents, to development stacks with the potencial to be vulnerable to supply chain attacks. We cover container hardening, Landlock rulesets, Seccomp BPF profiles, firewall rules, DNS allowlists, and CVE scanning and vulnerability management.