← Glossary

gVisor

User-space kernel from Google; stronger isolation than plain Docker; used when syscall-level isolation matters (cf. Firecracker).

See also: docker