With stuff like RootImage and the various isolation settings you can have a configurably sandboxed container right in systemd.
Or just use systemd-nspawn if you want it more preconfigured.
With stuff like RootImage and the various isolation settings you can have a configurably sandboxed container right in systemd.
Or just use systemd-nspawn if you want it more preconfigured.