If you are running containerized workloads on Red Hat OpenShift, then you already benefit from industry-leading process isolation. Security context constraints (SCC) restrict what pods can do, SELinux enforces mandatory access controls, cgroups limit resource consumption, and many permissive Linux capabilities are dropped by default. That said, all of these controls still operate on a shared host kernel.
Gain stronger pod isolation on Microsoft Azure Red Hat OpenShift with OpenShift sandboxed containers
calendar_today
July 24, 2026
domain
redhat