Updates
VMPLs can also be used for serverless container security updates. It is important to note that if the vulnerability is severe and the guest OS could be infected, then it is best to discard the cVM, otherwise VMPL's can be used to ease the update. New revisions containing a security update should be run on VMPL 2 to isolate them from the lower privileged revision running on VMPL 3. Then, after the revision containing the vulnerability has been removed, the newly created revision should be run at VMPL 3.
Last updated