Hacker Newsnew | past | comments | ask | show | jobs | submit | roboben's commentslogin

docker is not a security boundary but a resource boundary.

It is security boundary but a weak one. Escaping from docker is very hard.

> Escaping from docker is very hard.

You mean a microVM.

A docker LPE (local privilege escalation) requires a kernel exploit such as Copyfail would work under docker but not in a microVM.


yes only c8i, m8i and r8i instance types support it. It is called nested virtualization[1]

[1] https://aws.amazon.com/about-aws/whats-new/2026/02/amazon-ec...


Unfortunately supply is quite limited. If you want to horizontally scale on these instances you need to have a good relationship with AWS so they'll give you a big allocation before c9i is a thing.

I haven't personally tried, so I can't say for certain, but Lambda has publicly stated they run on bare metal EC2 instances, presumably the supply of whatever instance types they use should be fairly healthy

You're talking about AWS Lambda?

- Their use of bare metal isn't necessarily the latest gen hardware - AWS Lambda is part of AWS, and obviously has privileged access to supply


The interesting part to me is less the exact hardware generation and more the control plane around placement, isolation, and startup latency. That is hard to copy outside AWS.

also i found them much less stable than metal instances running into weird kvm failures

Yes, it is. It was a challenge to make it work smooth without metal. The scaling out speed was one of the main reasons

yep looks heavily inspired by OF. Anyone knows whats up with that project? I was involved years ago, it seems to still be going but I think many people moved on?


Hosted dashboard for your personal weather station.

https://weatherstage.com/

I had some custom build scripts and sites for my dad and myself and was thinking I could make a simple SaaS out of it. Super early and didn’t advertise anywhere yet since the actual dashboard is very simple right now but it works and I keep adding the features I want to use myself.

Example dashboard: https://warnitz.weatherstage.com/

If you want to try it out, I suggest you write me at hello at domain and I will get you going. Let me know the type of weather station you have!


They should have renamed it first to HashiCorp, an IBM Company CDK, then shut it down


Tried it, had some issue, opened a bug report, no response. I think it is dead.


Le chat doesn’t seem to know about this change despite the blog post stating it. Can anyone explain how to use it in Le Chat?


Looks to be API only for now. Documentation here: https://docs.mistral.ai/capabilities/document/


I asked LeChat this question:

If I upload a small PDF to you are you able to convert it to markdown?

LeChat said yes and away we went.


…and removed from front page…


Why did this post got removed from the front page?


Docker hub reported an incident[1] at the same time. Are they running on R2?

[1] https://www.dockerstatus.com/pages/incident/533c6539221ae15e...


looks like they do for free users.

https://docs.docker.com/desktop/setup/allow-list/


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: