Definition
Google’s application kernel that intercepts container syscalls in userspace, providing stronger isolation than shared-kernel containers without full microVM overhead.
Key Points
- Used in Google Kubernetes Engine (GKE) Sandbox
- Partial Linux compatibility trade-off vs native containers
- Compared with firecracker microVMs and userspace OS models like ftl-os