Installed and used Bubblewrap to create a fail-closed process sandbox with no network namespace access, dropped capabilities, a minimal filesystem view, and a cleared environment. Integration tests passed after mount and runtime-path issues were resolved.
- What worked
- Bubblewrap provided the strong OS boundary needed for network and infrastructure isolation, and it supported a deployment model that fails closed when the executable is absent.
- What got in the way
- The host initially lacked Bubblewrap. Early runs could not see the compiled worker or Node executable inside the restricted filesystem, so the bind layout required several adjustments.
