Skip to content

GEMINI_SANDBOX=GVISOR: enable sandboxing via gVisor #15875

@milantracy

Description

@milantracy

What would you like to be added?

To use gVisor's runsc as additional sandbox option for Gemini CLI

Why is this needed?

gVisor (https://github.com/google/gvisor) is an open source project that provides a strong layer of isolation between running applications and the host operating system.

It will be a good fit for providing a security barrier between AI operations and the host environment, which has been used by other players, e.g. https://www.reddit.com/r/ClaudeAI/comments/1pcama8/i_reverseengineered_claudes_code_execution/

Additional context

  • gVisor is available on Linux only

Metadata

Metadata

Assignees

Labels

area/platformIssues related to Build infra, Release mgmt, Testing, Eval infra, Capacity, Quota mgmthelp wantedWe will accept PRs from all issues marked as "help wanted". Thanks for your support!priority/p2Important but can be addressed in a future release.type/feature

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions