Tool Open source

gVisor

gVisor is an application kernel and container sandbox developed by Google that provides an isolation layer between containerized applications and the host operating system. Written in Go and running in user space, it implements a Linux-like interface while limiting the host-kernel surface available to applications. Its Open Container Initiative runtime, runsc, integrates with Docker and Kubernetes to run sandboxed containers, using a third approach distinct from syscall filters, wrappers around Linux isolation primitives, and conventional virtual machines.

View repository Visit site Mentioned in 2 videos ↓

What gVisor is used for

2 uses taken from transcripts — each links to the moment in the video.

  • A container runtime sandbox mentioned as an option for additional protection against container runtime escapes, though the hosts characterize it as operationally burdensome.

  • Provides a user-space system-call boundary used as part of the stronger sandbox isolation design.

Videos mentioning gVisor

2 in the library.