Linux Sandboxing & Confinement — seccomp-bpf, Landlock, gVisor, Kata, Firecracker

Parent: DevOps, Infrastructure & Observability · researched 2026-06-01T05:01:07.348Z· 19 sources · 8 concepts · skill devops-infra

DevOps / infrastructure / observability family ROUTER. Split into focused sub-hubs — route to: devops-linux-internals (kernel, boot, memory/NUMA, storage/filesystems, virtualization, io_uring, cgroups

devops-infra

Children

Frontier under this node: Firecracker minimal microVM monitor (5-device model, Jailer, ~125ms boot/<5MiB, Lambda/Fargate), Isolation-vs-performance decision model for choosing a boundary, Kata Containers VM-isolated OCI containers (shim/agent/guest-kernel/rootfs, QEMU vs Cloud Hypervisor vs Firecracker, TDX/SEV-SNP, runtime-rs), LSM framework + capabilities + SELinux/AppArmor/BPF-LSM context, Landlock unprivileged self-sandboxing LSM (ABI v1-v6, filesystem/REFER/TRUNCATE/network/ioctl/scoped-IPC rights, best-effort downgrade), Unprivileged userspace sandboxes (bubblewrap, nsjail, firejail), gVisor user-space kernel (Sentry, Gofer/9P + Directfs, runsc, ptrace->Systrap->KVM platforms), seccomp-bpf syscall filtering (cBPF over seccomp_data, eight RET actions, no_new_privs, TSYNC, SECCOMP_RET_USER_NOTIF notifier)

← the whole tree · 3D view· how to read this page