gVisor
Google's user-space application kernel for workload isolation, delivered as the runsc OCI runtime.
gVisor is Google's Apache-2.0 sandbox that implements a user-space application kernel (Sentry plus Gofer) and ships as the runsc OCI runtime; it is neither a hypervisor nor a syscall filter, and is used by Google Cloud Run and GKE Sandbox.
Caveat: The commonly quoted '200-500ms cold start' has no official published figure; observed numbers range widely (roughly 100ms to multiple seconds) depending on platform and configuration.
Key facts
| Category | Execution Sandbox |
|---|---|
| License | Apache-2.0 |
| Language | Go |
| Self-hosted | Yes |
| GitHub stars | 19,501 (2026-10-04) |
| Last push | 2026-10-04 |
| Last verified | 2026-10-04 |
| Repository | https://github.com/google/gvisor |
Tools in this category
Daytona
Agent sandboxes with independent kernel per sandbox and sub-90ms snapshot resume.
Firecracker
AWS's open-source microVM monitor powering Lambda and Fargate.
NVIDIA OpenShell
Policy-governed agent runtime that blocks all outbound network traffic by default.