GVisor is being donated to CNCF
Thread
Loading the complete thread in the background. This saved snapshot is available now. Refresh
Unofficial Hacker News client; not affiliated with Y Combinator.
GVisor is being donated to CNCF
Loading the complete thread in the background. This saved snapshot is available now. Refresh
Unofficial Hacker News client; not affiliated with Y Combinator.
mintflow · · focus · HN ↗
Hope this shift will make the project get sustainable and evolve fast
minraws · · focus · HN ↗
Though tbh I don't have much to complain about GVisor project, one of the nicer projects I have worked more with other things though but it's not that bad.
xyzzy_plugh · · focus · HN ↗
Frankly I would never want to operate gvisor with customer defined workloads.
For one, performance isn't native, which makes it hard to determine workload characteristics. Second, it has a pretty long list of limitations that make it difficult to deploy transparently: cgroups aren't fully supported, no io_uring, etc.
They claim they test a wide array of workloads but there are still compatibility issues that take years to iron out. I once had a workload that was probably buggy, and crashed only on arm64 under gvisor, but as I lacked source access there was no viable path forward.
I hope I am wrong, I'd love to see gvisor really take off. I think finishing the macOS port would be wild: run Linux binaries on macOS without a VM! But I'm not confident.
iercan · · focus · HN ↗
the article is quite pessimistic but looking at the latest cves found, most of them are mitigated: <a href="https://gvisor.dev/security-track-record/" rel="nofollow">https://gvisor.dev/security-track-record/ (and those are big ones currently, full container escapes..)
anotherhue · · focus · HN ↗
Last I looked (years) those were very much 'not intended use'.
trashcan2137 · · focus · HN ↗
bananaquant · · focus · HN ↗