Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Ah, I see what you’re saying. Basically, Darwin doesn’t support cgroups, so Docker runs Linux in a VM to get that.


I don't think it supports userland namespaces either, which is another important part of container isolation.


It has partial namespaces support for the iOS simulator.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: