Virtualization Innovations for Securing Containers: Aporeto at the BayLISA Meetup

Amir // November 12, 2016

As Docker and other container runtimes are growing their user base, the merits and the weaknesses of Linux containers as a technology for isolation are under scrutiny. Due to the large surface of attack exposed by the porous POSIX interface, avoiding multi-tenant containers deployments is still recommended. Clear Containers by Intel propose to solve the problem by running Docker containers as KVM virtual machines. Is that really the way forward?

