Skip to content
Better HN
Top
Best
Ask
Show
New
Jobs
Search
⌘K
0 points
bogomipz
3y ago
0 comments
Save
Share
In GKE you can just enable GKE Sandbox/gVisor on a node pool to run your untrusted workloads. gVisor serves the same purpose as Kata containers.
0 comments
3 comments · 1 top-level
top
newest
oldest
dilyevsky
3y ago
· 2 in thread
Yes except slow io
bogomipz
OP
3y ago
Can you elaborate? What type of I/O, network, disk? What is the issue exactly?
dilyevsky
3y ago
You can refer to gvisor performance docs -
https://gvisor.dev/docs/architecture_guide/performance/#file...
throughput is really terrible, same deal with networking and also if your userland issues a lot of syscalls
1 more reply
j
/
k
navigate · click thread line to collapse