Re: how to make a sandboxed environment in linux vps

The answer to this is that you can't, and since VPSs are $5/month or less for a cheap one, you should buy a second one.  Chroot, cgroups, and docker have all had bugs to one sort or another that allow escaping the sandbox.  Additionally, there's no good way to test whether or not it's actually secure, so it might look right but turn out not to be.  The only way to get a secure sandbox is to run a VM, but a vps may or may not let you.

Also, in some jurisdictions, combining your personal and business servers may be a way to do something called piercing the corporate veil, which puts you at extra legal liability if something goes wrong, so you should consult with a lawyer or something (unless you're 15, and "company" is actually "I made a blog", in which case you should learn the difference between them).

If you just need to run a couple static web sites, you can totally just configure nginx to point at different folders, though something like WordPress gets back to needing sandboxing (WordPress is a bad idea in general and if you need it you should pay someone else to deal with it, but no one around here gets that, so shrug).

-- 
Audiogames-reflector mailing list
Audiogames-reflector@sabahattin-gucukoglu.com
https://sabahattin-gucukoglu.com/cgi-bin/mailman/listinfo/audiogames-reflector
  • ... AudioGames . net Forum — Off-topic room : bhanuponguru via Audiogames-reflector
    • ... AudioGames . net Forum — Off-topic room : Meatbag via Audiogames-reflector
    • ... AudioGames . net Forum — Off-topic room : bhanuponguru via Audiogames-reflector
    • ... AudioGames . net Forum — Off-topic room : Meatbag via Audiogames-reflector
    • ... AudioGames . net Forum — Off-topic room : bhanuponguru via Audiogames-reflector
    • ... AudioGames . net Forum — Off-topic room : camlorn via Audiogames-reflector
    • ... AudioGames . net Forum — Off-topic room : bhanuponguru via Audiogames-reflector
    • ... AudioGames . net Forum — Off-topic room : jack via Audiogames-reflector

Reply via email to