AI Tools / AI products & services
An open-source sandboxed container runtime developed by Google that uses a user-space application kernel to isolate containers from the host kernel and reduce the impact of container escapes. Its OCI-compatible runsc runtime integrates with Docker, Kubernetes, and containerd and is implemented primarily in Go.
A container runtime sandbox mentioned as an option for additional protection against container runtime escapes, though the hosts characterize it as operationally burdensome.