gVisor

No phone app

7.3No. 9 of 30
in Container Engines
  • Recognised40% of the score57
  • Phone app26% of the score0
  • Documented20% of the score98
  • Free plan14% of the score100
Free plan
Yes
Runs on
Linux, self-hosted

Summary

gVisor is ranked #9 of 30 in container engines on Samsung Mobile US Press. It runs on Linux, Self-hosted. There is a free plan.

gVisor plans and pricing

All plans
gVisor Free Open-source Linux-compatible sandbox; requires Linux 5.6+ and x86_64 or ARM64 gvisor.dev · 4 Oct 2026

Compared on container engines

Free plan
Yesgvisor.dev
Rootless mode
Yesgvisor.dev
Image building
Yesgvisor.dev
Kubernetes CRI
Yesgvisor.dev
Windows containers
Nogvisor.dev
Image format
bothgvisor.dev
Runtime interface
othergvisor.dev
Supported host OS
Linuxgvisor.dev

Facts

Product
gVisor is an open-source Linux-compatible sandbox for running containers.gvisor.dev · 4 Oct 2026
Use case
It is designed to isolate hosts from untrusted code, including user-uploaded, LLM-generated, and third-party code.gvisor.dev · 4 Oct 2026
System call isolation
gVisor intercepts sandboxed applications’ system calls and implements them in its Sentry instead of passing them directly to the host.gvisor.dev · 4 Oct 2026
Defense in depth
The Sentry’s access to host system calls is minimized, and the site says gVisor runs with least privileges and a strict system call filter.gvisor.dev · 4 Oct 2026
Container integrations
The project documents use with Docker, Kubernetes, containerd, and OCI runtimes.gvisor.dev · 4 Oct 2026
Runtime monitoring
gVisor can stream application trace points to an external threat detection engine such as Falco to generate alerts.gvisor.dev · 4 Oct 2026
GPU support
gVisor supports most CUDA applications on selected NVIDIA driver versions, and the GPU application can run unmodified inside the sandbox.gvisor.dev · 4 Oct 2026
GPU limits
GPU support is limited to selected models, driver versions, capabilities, device files, ioctl calls, and platforms.gvisor.dev · 4 Oct 2026
Supported host
Installation requires Linux 5.6 or later and supports x86_64 and ARM64.gvisor.dev · 4 Oct 2026
Compatibility caveat
The application compatibility list is best-effort and does not guarantee that applications marked compatible are fully functional.gvisor.dev · 4 Oct 2026
Hardware security limit
gVisor generally does not protect against hardware side channels and relies on the host operating system and platform for those defenses.gvisor.dev · 4 Oct 2026
Support
The project directs users to GitHub issues, documentation, and mailing lists for support and community discussion.gvisor.dev · 4 Oct 2026
License and availability
gVisor is described on its official site as open-source software.gvisor.dev · 4 Oct 2026
Purpose
gVisor is an open-source Linux-compatible sandbox and application kernel that isolates containers from the host operating system.gvisor.dev · 4 Oct 2026
Untrusted workloads
It is intended to help safely run user-uploaded, LLM-generated, third-party, and other untrusted code.gvisor.dev · 4 Oct 2026
Security design
The Linux kernel and network stack components are written in Go, and gVisor runs with least privileges and a restrictive system call filter.gvisor.dev · 4 Oct 2026
Kubernetes options
The documentation describes running gVisor with GKE Sandbox, Minikube, or Kubernetes nodes configured with containerd and the gVisor shim.gvisor.dev · 4 Oct 2026
Architecture
A sandbox includes a Sentry application kernel that handles system calls and a Gofer process that mediates filesystem access.gvisor.dev · 4 Oct 2026
Checkpoint and restore
gVisor can checkpoint and restore containers for uses such as caching warmed services, resuming workloads on other machines, and saving state for forensics.gvisor.dev · 4 Oct 2026
Requirements
The installation guide says gVisor supports x86_64 and ARM64 and requires Linux 5.6 or later.gvisor.dev · 4 Oct 2026
Compatibility limit
gVisor does not implement every system call, /proc file, or /sys file, so some application incompatibilities may occur.gvisor.dev · 4 Oct 2026
Performance trade-off
The documentation notes that gVisor has higher per-system-call overhead and reduced application compatibility compared with other isolation approaches.gvisor.dev · 4 Oct 2026
Security reporting
The project asks that sensitive security reports be sent to its security mailing list or submitted privately through GitHub advisories, and says a response is typically provided within 48 hours.gvisor.dev · 4 Oct 2026

Best gVisor alternatives

See all 12

Where it ranks on Samsung Mobile US Press

Is gVisor yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources