• jabjoe@feddit.uk
    link
    fedilink
    English
    arrow-up
    1
    ·
    16 hours ago

    It’s so easy, why bother? But I have each service in a separate small Debian VM to avoid conflicts. This avoids conflicts, enforces limits, and gives kernel separation. The real kernel isn’t running anything public.

      • jabjoe@feddit.uk
        link
        fedilink
        English
        arrow-up
        1
        ·
        14 hours ago

        Containers are often used as a way to not have to keep things up to date, or install properly. Don’t have to be, but often are. Also, not have a separate kernel means you aren’t protected from things like the recent exploits when you allow things uploaded to run. Maintaining Debian Stable is easy really. Love me some Debian. 😀