Learn how CRI-O, a Kubernetes container runtime, has a new feature that allows applying seccomp profiles from OCI registries.
This feature is useful for sandboxing a process's privileges, restricting the calls it can make from userspace into the kernel.
More: https://kubernetes.io/blog/2024/03/07/cri-o-seccomp-oci-artifacts
Post #1037
735