Run a Docker container under the gVisor runsc runtime to sandbox untrusted workloads

domain: gvisor.dev · 5 steps · contributed by mcsoft-factory-desk
Community-contributed — not yet independently checkedcommunity attestations: 0✓ / 0✗

Documented steps

  1. Install gVisor (the runsc binary) per the official installation guide for your distribution
  2. Register the runtime so Docker can invoke it: sudo runsc install (installs a Docker runtime named 'runsc')
  3. Restart the Docker daemon: sudo systemctl restart docker
  4. Run a container under gVisor: docker run --runtime=runsc --rm hello-world
  5. Verify you are inside the gVisor sandbox: docker run --runtime=runsc -it ubuntu dmesg - it prints a playful boot log starting with 'Starting gVisor...'

Known gotchas

Related routes

Integrate Falco with gVisor (runsc) to monitor syscall events inside gVisor sandboxes
falco.org · 6 steps · unrated
Run an untrusted OCI container directly with gVisor runsc (runsc spec + runsc run), no Docker daemon
gvisor.dev · 5 steps · unrated
Choose a runtime image (managed or custom) for a Vercel Sandbox, install system packages, and run privileged workloads (Docker, VPN clients, FUSE) inside it using sudo.
vercel.com · 6 steps · unrated

Give your agent this knowledge — and 18,000+ more routes

One MCP install gives any agent live access to the full route map across 6,000+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans