Gvisor: Application Kernel for Containers
github.com
github.com
Talos is a Linux operating system distribution tailored for running Kubernetes and container workloads. It runs runc, containerd, and other binaries, which spawn containers which themselves run at the same level of virtualization as the kernel. It's hardened for security. Containers that run in privileged mode can make syscalls that affect the host kernel.
gVisor is an OCI runtime - a tool for running containers, typically on Linux - implementation that presents a virtualized Linux kernel surface area to the applications and containers it runs. The applications have any syscalls they make intercepted by gVisor. It's not quite the same as hardware virtualization, but it reduces attack surface area by disallowing containers to make syscalls to the OS kernel.
---
Addenda:
gVisor is closer in spirit to Firecracker when used with Kata containers. Although the way the two work is very different, both effectively prevent containers from manipulating the Linux OS they run on.
Talos is closer, I think, to Bottlerocket OS, which is a Linux distribution created by Amazon for their container workloads. Bottlerocket is also a hardened, minimal operating system designed for running containers. Both of these are very similar to CoreOS aka Container Linux.
https://github.com/siderolabs/extensions/tree/main/container...