Building rootless Linux Sandboxes from first principles
Raunak Ramakrishnan
Why Rootless Sandboxing Matters
User Namespaces - Least Privilege Identity
Seccomp: System Call Filtering
Landlock: User-Space Policy Enforcement
Filesystem Views: Reducing What a Process Can See
Userspace Networking - Why is it not straightforward
Demo