Posts tagged #isolation
-
Kata Containers: how every CI job gets its own kernel
Ordinary containers share the host kernel. Kata Containers runs each pod in a lightweight VM with its own guest kernel — OCI-compatible, under containerd. A look at the Kata 3.x architecture and why it's the right boundary for untrusted CI code.