AI Potluck
Infrastructure / Deployment

gVisor

Google

gVisor application-kernel sandbox; repo live June 2026 (rolling date-tagged releases, no GitHub Releases page). Go userspace kernel intercepting syscalls (Sentry + Gofer); used as the sandbox runtime behind Google Cloud Run and GKE Sandbox.

gVisor application-kernel sandbox; repo live June 2026 (rolling date-tagged releases, no GitHub Releases page). Go userspace kernel intercepting syscalls (Sentry + Gofer); powers Google Cloud Run.

Openness

5 high confidence
5.0
license
Apache-2.0(OSI)
source
public(Go)
governance
Google-led open project
core-gated
ungated

Fully Apache-2.0 application kernel, source public, no gated core (recipe lists gVisor as an open_source exemplar).

Adoption

5 high confidence
5.0

Underpins Google Cloud Run ('Powered by gVisor' on gvisor.dev) and is the sandbox layer for GKE Sandbox / App Engine / Cloud Functions, billions of container executions across Google Cloud. Reach far exceeds >10M end-equivalent. (18.5k stars corroborate only.)

Capability

5 high confidence
5.0

Frontier-definer: a novel application-kernel isolation model giving VM-class security at userspace footprint/startup, the reference sandbox for Google Cloud's serverless containers. Co-frontier with Firecracker (different isolation philosophy).

  • https://github.com/google/gvisor recorded 2026-06-04

    intercepts syscalls as a userspace application kernel; VM-class security benefits at userspace footprint and startup

Unchanged since 2026-07-30 (last edited, not re-checked)