Sandboxing with minimal effort
Inko now offers an application-level sandbox API that maps simple file and network permissions onto OS primitives such as Linux Landlock. The example server needs only explicit read access to its content and TLS directories plus permission to bind its TCP port; everything else is denied on supported platforms.
The trade-off is portability: the API currently does nothing on FreeBSD because Capsicum requires deeper program-structure changes. A Lobsters commenter also warns that unsupported restrictions can silently become no-ops, and that Landlock ABI differences and access to sockets, devices, or GPUs complicate real deployments. The article presents this as a usability win, not a substitute for externally enforced isolation.