GVisor is being donated to CNCF
birdculture
22 points
7 comments
October 04, 2026
Related Discussions
Found 5 related stories in 84.8ms across 8,480 title embeddings via pgvector HNSW
- Show HN: Drop – A rootless Linux sandbox with gVisor support mixedbit · 162 pts · September 22, 2026 · 46% similar
- GCC AI Policy Announcement signa11 · 31 pts · September 13, 2026 · 41% similar
- Show HN: Kurvengefahr – browser CAD/CAM for pen plotters tibordp · 18 pts · July 12, 2026 · 41% similar
- EDG C++ front-end goes public iandinwoodie · 193 pts · September 30, 2026 · 41% similar
- Donate to GrapheneOS charliebwrites · 238 pts · July 28, 2026 · 40% similar
Discussion Highlights (7 comments)
mintflow
The networking stack is actually used by many open source project such as tailscale Hope this shift will make the project get sustainable and evolve fast
minraws
Alright does this also mean we are detaching some of the google specific stuff and or are more accepting of open standards related changes? Though tbh I don't have much to complain about GVisor project, one of the nicer projects I have worked more with other things though but it's not that bad.
xyzzy_plugh
I like gvisor but I fear this is too little, too late. Microvms are crushing it right now. I believe even Modal, which is one of the few non-Google users deploying gvisor commercially, and heavily called out in TFA, are moving off gvisor in favor of microvms. Unreal! Frankly I would never want to operate gvisor with customer defined workloads. For one, performance isn't native, which makes it hard to determine workload characteristics. Second, it has a pretty long list of limitations that make it difficult to deploy transparently: cgroups aren't fully supported, no io_uring, etc. They claim they test a wide array of workloads but there are still compatibility issues that take years to iron out. I once had a workload that was probably buggy, and crashed only on arm64 under gvisor, but as I lacked source access there was no viable path forward. I hope I am wrong, I'd love to see gvisor really take off. I think finishing the macOS port would be wild: run Linux binaries on macOS without a VM! But I'm not confident.
iercan
gVisor is still pretty useful for untrusted workloads when you don't have KVM, though it gets harder to integrate into workflows where people are running macOS/windows locally the article is quite pessimistic but looking at the latest cves found, most of them are mitigated: https://gvisor.dev/security-track-record/ (and those are big ones currently, full container escapes..)
anotherhue
Does anyone know if it has capabilities that would be useful in running retro-games? I'm imagining a guest KMS-> host SDL conversion, or indeed something like virtio-gpu? Last I looked (years) those were very much 'not intended use'.
trashcan2137
They don't even sufficiently describe what it actually does and why it would be a better choice than a micro VM or whatever you call it these days
bananaquant
Good night, GVisor.