Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Investigate gVisor #94

Open
xunholy opened this issue Aug 30, 2020 · 3 comments
Open

Investigate gVisor #94

xunholy opened this issue Aug 30, 2020 · 3 comments
Labels
bug Something isn't working enhancement New feature or request feature_request question Further information is requested

Comments

@xunholy
Copy link
Owner

xunholy commented Aug 30, 2020

Details

https://github.com/google/gvisor

Note: Currently supports ARM64

@xunholy xunholy added the enhancement New feature or request label Aug 30, 2020
@issue-label-bot
Copy link

Issue-Label Bot is automatically applying the label feature_request to this issue, with a confidence of 0.83. Please mark this comment with 👍 or 👎 to give our bot feedback!

Links: app homepage, dashboard and code for this bot.

@carpenike
Copy link
Contributor

Interesting...

https://gvisor.dev/docs/user_guide/containerd/quick_start/

I get the feeling this would introduce a layer that would become a pita to troubleshoot.

@xunholy
Copy link
Owner Author

xunholy commented Sep 1, 2020

@carpenike gvisor provides a lot of additional security if my k8s cluster were to be compromised.

Interestingly I have found some open issues in conjunction with using gvisor and istio together - google/gvisor#170

@xunholy xunholy added bug Something isn't working question Further information is requested labels Oct 16, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working enhancement New feature or request feature_request question Further information is requested
Projects
None yet
Development

No branches or pull requests

2 participants