Notes / Kubernetes / 07 Kubernetes Security / 9 Sandboxed Containers Gvisor Kata

9 — Sandboxed Containers (gVisor, Kata)

gVisor intercepts syscalls through a userspace kernel while Kata runs each pod inside a lightweight VM, and both trade some raw performance for a dramatically smaller attack surface than a shared-kernel container runtime.

· §202607201139-65 ·
Chapter Navigation
On This Page

9 — Sandboxed Containers (gVisor, Kata)

Purpose

[stub: sandboxed-containers-gvisor-kata]

Metadata

AuthorAmit Singh
Scopekubernetes

Local graph

Full graph →