← Glossary

Docker

OS-level virtualization used to bound the agent’s filesystem and processes. Most agent sandboxes are a Docker image.

Also known as: container

See also: gvisor, seccomp