01

Research question

Which isolation substrate fits each trust level and workload?

02

Key findings

  • Containers fit trusted internal workloads but do not automatically satisfy public untrusted multi-tenancy.
  • gVisor strengthens the syscall boundary while requiring ongoing compatibility validation.
  • MicroVMs provide a clearer kernel boundary at the cost of image, network, and scheduling complexity.
03

Method and limitations

This version is desk research based on public repositories, official documentation, and architecture material. Vendor claims about performance, security, and compatibility require independent experiments on pinned versions before becoming Live Verified.

04

Sources