Back
Google is donating its sandboxed container runtime gVisor to CNCF
SiTech AI Team3 min read

Google is donating its sandboxed container runtime gVisor to CNCF

Google has donated gVisor, the sandboxed container runtime it open-sourced in 2018, to the Cloud Native Computing Foundation. CNCF accepted the application on September 28, and the project is moving to maintainers-based governance.

Google is donating the gVisor project, including its name and trademarks, to the Cloud Native Computing Foundation (CNCF), a subsidiary of the Linux Foundation. The project's contributors announced the move in a blog post published on October 2. gVisor is a sandboxed container runtime that Google open-sourced in 2018 under the Apache 2.0 license; according to its contributors, it has remained the second most mature implementation of Linux ever since, after Linux itself.

What has already happened

The donation application was submitted on September 7. CNCF reviewed it on September 22 and accepted it on September 28. Over the coming weeks, the project will move to CNCF "Sandbox" status, its build and testing infrastructure will shift to GitHub Actions and Buildkite, and Google's internal tests will no longer block pull requests. Governance will transition to a maintainers-based model: non-Google maintainers will be added and given merge permissions. Within months, the project aims for CNCF "Incubation" status, its repository will leave the google GitHub organization, and governance will adopt org-based voting, ending Google's unilateral control.

Why Google is donating gVisor

Two long-running problems drove the move. gVisor straddles the industry's divide between plain containers and virtual machines: it offers what the contributors call empirically-equivalent security, but without the "virtualization" checkbox that auditors and regulators often treat as a proxy for security. The project also has a performance-perception problem: Google and companies such as Ant Group and Modal run Linux kernel patches that significantly improve gVisor, but out-of-the-box performance still degrades on some I/O-intensive workloads, creating poor first impressions. Attempts to upstream those patches were turned down by kernel maintainers because gVisor was a wholly-owned Google project.

Google also wants gVisor to serve goals that corporate ownership made hard to prioritize: running Linux programs on macOS (gVisor-on-Mac, in the spirit of Wine) and desktop Linux application sandboxing that is more secure than bubblewrap, flatpak or nsjail, yet easier to integrate than virtualization-based approaches such as Qubes OS.

New maintainers and next steps

Ant Group, Modal and Tines have committed to joining gVisor's maintainers long term, while OpenAI, Tencent and NVIDIA will continue contributing. gVisor integrates directly with CNCF technologies such as Kubernetes, containerd and Agent Substrate. Its container-like process model packs secure workloads at a density VM-based runtimes cannot match, and it needs no hardware or nested virtualization, so it runs anywhere Linux runs. Some contributors will be at KubeCon North America 2026.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.