epappas's profile
Evangelos Pappas@epappas•Feb 11
40
Post cover image

I am breaking my head in Analyzing Container Filesystem Isolation For Multi-Tenant Workloads, so you don’t have to

From medium.com•Feb 11•45m read time

Container filesystem isolation defaults protect well, but advanced features like bidirectional mount propagation or SELinux relabeling can create host compromise vectors. The kernel auto-demotes shared mounts to MS_SLAVE in less-privileged namespaces, and seccomp blocks mount() by default before AppArmor/SELinux enforcement. OverlayFS kernel bugs (CVE-2023-0386) bypass all container isolation. For untrusted multi-tenant workloads, consider gVisor or Firecracker/Kata instead of relying solely on namespace isolation.

3 Impressions
epappas's user avatar
Evangelos Pappas
@epappas
Joined Feb 9. 2026
40

Systems and Platform engineer for large scale GPU clusters

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard