mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
docs: update manifest in docs (#21434)
Follow-up for https://github.com/coder/coder/pull/21420
This commit is contained in:
@@ -107,9 +107,9 @@ curl -fsSL https://raw.githubusercontent.com/coder/boundary/main/install.sh | ba
|
||||
|
||||
Boundary supports two different jail types for process isolation, each with different characteristics and requirements:
|
||||
|
||||
1. **nsjail** - Uses Linux namespaces for isolation. This is the default jail type and provides network namespace isolation. See [nsjail documentation](nsjail.md) for detailed information about runtime requirements and Docker configuration.
|
||||
1. **nsjail** - Uses Linux namespaces for isolation. This is the default jail type and provides network namespace isolation. See [nsjail documentation](./nsjail.md) for detailed information about runtime requirements and Docker configuration.
|
||||
|
||||
2. **landjail** - Uses Landlock V4 for network isolation. This provides network isolation through the Landlock Linux Security Module (LSM) without requiring network namespace capabilities. See [landjail documentation](landjail.md) for implementation details.
|
||||
2. **landjail** - Uses Landlock V4 for network isolation. This provides network isolation through the Landlock Linux Security Module (LSM) without requiring network namespace capabilities. See [landjail documentation](./landjail.md) for implementation details.
|
||||
|
||||
The choice of jail type depends on your security requirements, available Linux capabilities, and runtime environment. Both nsjail and landjail provide network isolation, but they use different underlying mechanisms. nsjail uses Linux namespaces, while landjail uses Landlock V4. Landjail may be preferred in environments where namespace capabilities are limited or unavailable.
|
||||
|
||||
|
||||
+13
-1
@@ -961,7 +961,19 @@
|
||||
"title": "Agent Boundaries",
|
||||
"description": "Understanding Agent Boundaries in Coder Tasks",
|
||||
"path": "./ai-coder/agent-boundary.md",
|
||||
"state": ["early access"]
|
||||
"state": ["beta"],
|
||||
"children": [
|
||||
{
|
||||
"title": "nsjail",
|
||||
"description": "Documentation for Namespace Jail",
|
||||
"path": "./ai-coder/nsjail.md"
|
||||
},
|
||||
{
|
||||
"title": "landjail",
|
||||
"description": "Documentation for LandJail",
|
||||
"path": "./ai-coder/landjail.md"
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"title": "AI Bridge",
|
||||
|
||||
Reference in New Issue
Block a user