• thedeadwalking4242@lemmy.world
    link
    fedilink
    arrow-up
    5
    arrow-down
    1
    ·
    4 months ago

    Nix apps are not sandboxed and you have no control of what resources they have access to or don’t, unless you wrap them with some other program

    • Joenocide Biden@lemmy.ml
      link
      fedilink
      English
      arrow-up
      2
      ·
      edit-2
      4 months ago

      They can be isolated because Nix has in-built support for three different levels of sandboxing - virtual machines, containers as well as ephemeral shells.