• thedeadwalking4242@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    3 months ago

    Nix apps are not sandboxed and you have no control of what resources they have access to or don’t, unless you wrap them with some other program

    • LalSalaamComrade@lemmy.ml
      link
      fedilink
      English
      arrow-up
      0
      ·
      edit-2
      3 months ago

      They can be isolated because Nix has in-built support for three different levels of sandboxing - virtual machines, containers as well as ephemeral shells.