Back when we started gVisor I never imagined we'd run anything this complex. It's amazing to see how far the project has come!
gvisor.dev/blog/2026/09...
Back when we started gVisor I never imagined we'd run anything this complex. It's amazing to see how far the project has come!
gvisor.dev/blog/2026/09...
"A full NixOS system that you boot and then kick off agent sandboxes inside with gVisor + /nix/store namespace mounting. Each agent gets their own kernel and the /nix/store is read only by nature.
"A full NixOS system that you boot and then kick off agent sandboxes inside with gVisor + /nix/store namespace mounting. Each agent gets their own kernel and the /nix/store is read only by nature.
It took 77 LOCs of pure Go to add the UEFI driver and bridge it to gVisor stack.
It took 77 LOCs of pure Go to add the UEFI driver and bridge it to gVisor stack.
TamaGo+gVisor outperforms Linux (native or gVisor) by a ratio range of 50% - 500% (depending on packet size and core count).
Test envs are simpler than prod, but I think this is promising.
TamaGo+gVisor outperforms Linux (native or gVisor) by a ratio range of 50% - 500% (depending on packet size and core count).
Test envs are simpler than prod, but I think this is promising.
La sécurité se gère sur tout les plans : réseaux, privilèges, conteneurs/microVM, gvisor...
La sécurité se gère sur tout les plans : réseaux, privilèges, conteneurs/microVM, gvisor...
This article provides a guide demonstrating how to deploy gVisor on Ubuntu VPS.
Introduction
gVisor is an open-source application kernel developed by Google that provides an additional security layer between containerized ...
Continued 👉 #nginx
https://www.tpp.blog/16w7i4e
#cybersecurity #google #gvisor
https://www.tpp.blog/16w7i4e
#cybersecurity #google #gvisor
xint.io/blog/copy-fa...
I am going to link to this while rejecting changes to Go crypto for years.
Anyway, feeling pretty validated in my "ssh in as root, only gVisor or Firecracker are an actual security boundary" approach.
xint.io/blog/copy-fa...
I am going to link to this while rejecting changes to Go crypto for years.
Anyway, feeling pretty validated in my "ssh in as root, only gVisor or Firecracker are an actual security boundary" approach.
gomoot.com/drop-la-sand...
#drop #gvisor #kernel #Linux #opensource #sandbox
gomoot.com/drop-la-sand...
#drop #gvisor #kernel #Linux #opensource #sandbox
Una conversación con un cliente:
"Desplegamos agentes en un entorno protegido con contenedores manejados con gVisor, Spiffe, mTLS y un control de actividad interna: pasan por nuestra APIgateaway y tienen una baseline de comportamiento"
El cliente "ya... pero cómo me aseguras que..."
Una conversación con un cliente:
"Desplegamos agentes en un entorno protegido con contenedores manejados con gVisor, Spiffe, mTLS y un control de actividad interna: pasan por nuestra APIgateaway y tienen una baseline de comportamiento"
El cliente "ya... pero cómo me aseguras que..."
github.com/google/gviso...
github.com/google/gviso...
WarpStream
Turbopuffer
LanceDB
Neon
AWS Neptune
TigerBeetle
Modal
Materialize
Tabular (Iceberg)
DuckDB/Motherduck
Arrow Data Fusion/Substrate
gvisor
KIP-932 (Kafka)
VeniceDB
Bauplan
Buf schema registry
Apicurio
WarpStream
Turbopuffer
LanceDB
Neon
AWS Neptune
TigerBeetle
Modal
Materialize
Tabular (Iceberg)
DuckDB/Motherduck
Arrow Data Fusion/Substrate
gvisor
KIP-932 (Kafka)
VeniceDB
Bauplan
Buf schema registry
Apicurio
failed experiments so far:
- wasm/wasi
- go-landlock
capital-P project deferred: gVisor or firecracker
failed experiments so far:
- wasm/wasi
- go-landlock
capital-P project deferred: gVisor or firecracker
I am so grateful to the gVisor team for allowing me to put their pure Go TCP/IP stack on the bare metal.
All of this is now in go-boot@development and will be part of v1.1:
github.com/usbarmory/go...
I am so grateful to the gVisor team for allowing me to put their pure Go TCP/IP stack on the bare metal.
All of this is now in go-boot@development and will be part of v1.1:
github.com/usbarmory/go...