• thedeadwalking4242@lemmy.world
    link
    fedilink
    arrow-up
    6
    arrow-down
    1
    ·
    21 days ago

    Nix apps are not sandboxed and you have no control of what resources they have access to or don’t, unless you wrap them with some other program

    • LalSalaamComrade@lemmy.ml
      link
      fedilink
      English
      arrow-up
      2
      ·
      edit-2
      21 days ago

      They can be isolated because Nix has in-built support for three different levels of sandboxing - virtual machines, containers as well as ephemeral shells.