Tool Open source
gVisor is an application kernel and container sandbox developed by Google that provides an isolation layer between containerized applications and the host operating system. Written in Go and running in user space, it implements a Linux-like interface while limiting the host-kernel surface available to applications. Its Open Container Initiative runtime, runsc, integrates with Docker and Kubernetes to run sandboxed containers, using a third approach distinct from syscall filters, wrappers around Linux isolation primitives, and conventional virtual machines.
2 uses taken from transcripts — each links to the moment in the video.
A container runtime sandbox mentioned as an option for additional protection against container runtime escapes, though the hosts characterize it as operationally burdensome.
Provides a user-space system-call boundary used as part of the stronger sandbox isolation design.
2 in the library.