• LalSalaamComrade
    link
    fedilink
    English
    arrow-up
    2
    ·
    edit-2
    20 days ago

    They can be isolated because Nix has in-built support for three different levels of sandboxing - virtual machines, containers as well as ephemeral shells.