gVisor
No phone app
7.3No. 9 of 30
in Container Engines
in Container Engines
- Recognised40% of the score57
- Phone app26% of the score0
- Documented20% of the score98
- Free plan14% of the score100
- Free plan
- Yes
- Runs on
- Linux, self-hosted
Summary
gVisor is ranked #9 of 30 in container engines on Samsung Mobile US Press. It runs on Linux, Self-hosted. There is a free plan.
gVisor plans and pricing
All plansgVisor Free Open-source Linux-compatible sandbox; requires Linux 5.6+ and x86_64 or ARM64 gvisor.dev · 4 Oct 2026
Compared on container engines
- Free plan
- Yesgvisor.dev
- Rootless mode
- Yesgvisor.dev
- Image building
- Yesgvisor.dev
- Kubernetes CRI
- Yesgvisor.dev
- Windows containers
- Nogvisor.dev
- Image format
- bothgvisor.dev
- Runtime interface
- othergvisor.dev
- Supported host OS
- Linuxgvisor.dev
Facts
- Product
- gVisor is an open-source Linux-compatible sandbox for running containers.gvisor.dev · 4 Oct 2026
- Use case
- It is designed to isolate hosts from untrusted code, including user-uploaded, LLM-generated, and third-party code.gvisor.dev · 4 Oct 2026
- System call isolation
- gVisor intercepts sandboxed applications’ system calls and implements them in its Sentry instead of passing them directly to the host.gvisor.dev · 4 Oct 2026
- Defense in depth
- The Sentry’s access to host system calls is minimized, and the site says gVisor runs with least privileges and a strict system call filter.gvisor.dev · 4 Oct 2026
- Container integrations
- The project documents use with Docker, Kubernetes, containerd, and OCI runtimes.gvisor.dev · 4 Oct 2026
- Runtime monitoring
- gVisor can stream application trace points to an external threat detection engine such as Falco to generate alerts.gvisor.dev · 4 Oct 2026
- GPU support
- gVisor supports most CUDA applications on selected NVIDIA driver versions, and the GPU application can run unmodified inside the sandbox.gvisor.dev · 4 Oct 2026
- GPU limits
- GPU support is limited to selected models, driver versions, capabilities, device files, ioctl calls, and platforms.gvisor.dev · 4 Oct 2026
- Supported host
- Installation requires Linux 5.6 or later and supports x86_64 and ARM64.gvisor.dev · 4 Oct 2026
- Compatibility caveat
- The application compatibility list is best-effort and does not guarantee that applications marked compatible are fully functional.gvisor.dev · 4 Oct 2026
- Hardware security limit
- gVisor generally does not protect against hardware side channels and relies on the host operating system and platform for those defenses.gvisor.dev · 4 Oct 2026
- Support
- The project directs users to GitHub issues, documentation, and mailing lists for support and community discussion.gvisor.dev · 4 Oct 2026
- License and availability
- gVisor is described on its official site as open-source software.gvisor.dev · 4 Oct 2026
- Purpose
- gVisor is an open-source Linux-compatible sandbox and application kernel that isolates containers from the host operating system.gvisor.dev · 4 Oct 2026
- Untrusted workloads
- It is intended to help safely run user-uploaded, LLM-generated, third-party, and other untrusted code.gvisor.dev · 4 Oct 2026
- Security design
- The Linux kernel and network stack components are written in Go, and gVisor runs with least privileges and a restrictive system call filter.gvisor.dev · 4 Oct 2026
- Kubernetes options
- The documentation describes running gVisor with GKE Sandbox, Minikube, or Kubernetes nodes configured with containerd and the gVisor shim.gvisor.dev · 4 Oct 2026
- Architecture
- A sandbox includes a Sentry application kernel that handles system calls and a Gofer process that mediates filesystem access.gvisor.dev · 4 Oct 2026
- Checkpoint and restore
- gVisor can checkpoint and restore containers for uses such as caching warmed services, resuming workloads on other machines, and saving state for forensics.gvisor.dev · 4 Oct 2026
- Requirements
- The installation guide says gVisor supports x86_64 and ARM64 and requires Linux 5.6 or later.gvisor.dev · 4 Oct 2026
- Compatibility limit
- gVisor does not implement every system call, /proc file, or /sys file, so some application incompatibilities may occur.gvisor.dev · 4 Oct 2026
- Performance trade-off
- The documentation notes that gVisor has higher per-system-call overhead and reduced application compatibility compared with other isolation approaches.gvisor.dev · 4 Oct 2026
- Security reporting
- The project asks that sensitive security reports be sent to its security mailing list or submitted privately through GitHub advisories, and says a response is typically provided within 48 hours.gvisor.dev · 4 Oct 2026
Best gVisor alternatives
See all 12Where it ranks on Samsung Mobile US Press
Is gVisor yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- gvisor.dev· checked 4 Oct 2026
- gvisor.dev/docs/architecture_guide/security/· checked 4 Oct 2026
- gvisor.dev/docs/user_guide/gpu/· checked 4 Oct 2026
- gvisor.dev/docs/user_guide/install/· checked 4 Oct 2026
- gvisor.dev/application-compatibility/· checked 4 Oct 2026
- gvisor.dev/docs/· checked 4 Oct 2026
- gvisor.dev/docs/user_guide/quick_start/kubernetes/· checked 4 Oct 2026
- gvisor.dev/security/· checked 4 Oct 2026


