![]()
SHOP:楽天Kobo電子書籍ストア
1,583円(税込) (送料込) (カード利用可)
| 楽天市場で商品詳細を見る |
<p>"gVisor for Isolation: Sandboxed Containers Without Full VMs"</p> <p>Modern container platforms deliver speed and density, but their security story still hinges on a shared host kernel. This book is written for experienced engineersーsecurity practitioners, platform and SRE teams, and advanced container usersーwho need a precise, operational understanding of where classic container isolation ends and where gVisor meaningfully changes the risk profile. It treats isolation as an engineering discipline: explicit boundaries, measurable attack-surface reduction, and production-grade practices rather than folklore.</p> <p>You’ll build a rigorous model of namespaces, cgroups, and the shared-kernel threat, then learn how gVisor re-implements substantial Linux kernel behavior in userspace through the Sentry and mediates host interaction through the Gofer. The book drills into OCI integration via runsc, shows how to prove the sandbox is actually in use (and detect silent fallbacks), and provide...楽天市場のショップで商品詳細の続きを見る