Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
runsc: allow port-forwarding with network isolation
The security implications by this change are not entirely understood. At the most basic level, there can now be a port inside the sandbox that allows a network connection to the outside. Network isolation should prevent that. In Continuum's case this is fine because the other end outside the sandbox is expected to encrypt all sensitive data.
- Loading branch information