Skip to content

study: investigate runtime enforcer visibility into gVisor/runsc containers #574

@dottorblaster

Description

@dottorblaster

We want to understand whether the enforcer can provide meaningful visibility into gVisor/runsc containers.

gVisor's Sentry intercepts guest syscalls in userspace, so sandboxed workloads don't issue "real" syscalls from the host's point of view. This breaks most assumptions our eBPF probes rely on. We need to quantify the gap before deciding if there's something to build.

Acceptance criteria

  • Capability matrix: feature → { works / partial / blind } with one-line rationale.
  • Root-cause notes for "blind" cases.
  • Recommendation: doc gap, product gap, or "don't support".

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No fields configured for Task.

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions