gVisor
GooglegVisor application-kernel sandbox; repo live June 2026 (rolling date-tagged releases, no GitHub Releases page). Go userspace kernel intercepting syscalls (Sentry + Gofer); used as the sandbox runtime behind Google Cloud Run and GKE Sandbox.
gVisor application-kernel sandbox; repo live June 2026 (rolling date-tagged releases, no GitHub Releases page). Go userspace kernel intercepting syscalls (Sentry + Gofer); powers Google Cloud Run.
Openness
5 high confidence- license
- Apache-2.0(OSI)
- source
- public(Go)
- governance
- Google-led open project
- core-gated
- ungated
Fully Apache-2.0 application kernel, source public, no gated core (recipe lists gVisor as an open_source exemplar).
- https://github.com/google/gvisor recorded 2026-06-04
Apache-2.0 license; application kernel implementing Linux-like interface in userspace (Go)
Adoption
5 high confidenceUnderpins Google Cloud Run ('Powered by gVisor' on gvisor.dev) and is the sandbox layer for GKE Sandbox / App Engine / Cloud Functions, billions of container executions across Google Cloud. Reach far exceeds >10M end-equivalent. (18.5k stars corroborate only.)
- https://gvisor.dev/docs/ recorded 2026-06-04
'Powered by gVisor' linking to Google Cloud Run as a production user
- https://github.com/google/gvisor recorded 2026-06-04
Google-developed sandbox application kernel in production
Capability
5 high confidenceFrontier-definer: a novel application-kernel isolation model giving VM-class security at userspace footprint/startup, the reference sandbox for Google Cloud's serverless containers. Co-frontier with Firecracker (different isolation philosophy).
- https://github.com/google/gvisor recorded 2026-06-04
intercepts syscalls as a userspace application kernel; VM-class security benefits at userspace footprint and startup
Unchanged since 2026-07-30 (last edited, not re-checked)