gVisor is being donated to CNCF

gVisor is being donated to CNCF

gVisor 正式捐赠给 CNCF

By Etienne Perot and Jing Chen on 02 October 2026 作者:Etienne Perot 和 Jing Chen,2026 年 10 月 2 日

In 2018, Google open-sourced gVisor under the Apache 2.0 license. To the best of its contributors’ knowledge, it has ever since remained the second most mature implementation of Linux, after Linux. This year, the gVisor project is being donated to CNCF, and its governance model is shifting accordingly. 2018 年,Google 在 Apache 2.0 许可下开源了 gVisor。据贡献者所知,自那时起,它一直是继 Linux 内核之后,成熟度排名第二的 Linux 实现。今年,gVisor 项目正式捐赠给云原生计算基金会(CNCF),其治理模式也将随之转型。

What’s happening?

发生了什么?

Google is donating the gVisor project, including its name and trademarks, to the Cloud Native Computing Foundation (CNCF), a subsidiary of the Linux Foundation. Like its name implies, CNCF is focused on cloud-native computing, with Google having seeded its creation by donating the Kubernetes project. Since then, Kubernetes has grown to become the industry-standard for container orchestration, and has grown a large and vibrant ecosystem around it. gVisor is now following the same footsteps. You can see gVisor’s CNCF application and process. Google 正在将 gVisor 项目(包括其名称和商标)捐赠给 Linux 基金会的子公司——云原生计算基金会(CNCF)。顾名思义,CNCF 专注于云原生计算,而 Google 当初正是通过捐赠 Kubernetes 项目开启了 CNCF 的创建。自那时起,Kubernetes 已成长为容器编排的行业标准,并围绕其构建了一个庞大且充满活力的生态系统。如今,gVisor 正在追随同样的脚步。您可以查看 gVisor 的 CNCF 申请及流程。

What’s the timeline?

时间表如何?

What has already happened: 已完成事项:

  • 2026-09-07: Google submitted its CNCF donation application.
  • 2026-09-07:Google 提交了 CNCF 捐赠申请。
  • 2026-09-22: The CNCF reviewed the application.
  • 2026-09-22:CNCF 审核了该申请。
  • 2026-09-28: The application was accepted.
  • 2026-09-28:申请获得通过。
  • 2026-10-02: This blog post was published.
  • 2026-10-02:发布本篇博客文章。

Over the next few weeks: 未来几周内:

  • The project will move to CNCF “Sandbox” status (quite appropriately-named for a project like gVisor).
  • 该项目将进入 CNCF “沙箱(Sandbox)”状态(对于像 gVisor 这样的项目来说,这个名字非常贴切)。
  • gVisor’s build and testing infrastructure will move to GitHub Actions and Buildkite.
  • gVisor 的构建和测试基础设施将迁移至 GitHub Actions 和 Buildkite。
  • Google’s internal gVisor test infrastructure will no longer block PRs.
  • Google 内部的 gVisor 测试基础设施将不再阻塞 PR(合并请求)。
  • The gVisor project’s governance model will transition to a maintainers-based model. Non-Google maintainers will be added and given merge permissions.
  • gVisor 项目的治理模式将过渡到基于维护者的模式。非 Google 员工的维护者将被加入,并获得合并权限。

Over the next few months: 未来几个月内:

  • The project will take the steps needed to move to CNCF “Incubation” status.
  • 项目将采取必要步骤,向 CNCF “孵化(Incubation)”状态迈进。
  • The GitHub repository will move out of the google GitHub organization.
  • GitHub 仓库将从 google 组织中迁出。
  • The gVisor project’s governance model will transition to a long-term model that features org-based voting, thereby preventing Google from having unilateral control over governance decisions.
  • gVisor 项目的治理模式将过渡到一种长期的、基于组织投票的模式,从而防止 Google 对治理决策拥有单方面控制权。
  • Any further steps to become a fully-fledged CNCF project will proceed.
  • 成为成熟 CNCF 项目的后续步骤将继续推进。

Why donate?

为什么要捐赠?

gVisor doesn’t fit neatly into the industry’s well-known boxes of the sandboxing/security landscape, which tends to separate “vanilla containers” from “virtual machines” with shades of gray in between. gVisor straddles this middle-ground, providing empirically-equivalent security but without checking the familiar “virtualization” checkbox that security auditors, regulators, or security practitioners often treat as a one-to-one proxy for “secure”. This has caused adoption challenges over gVisor’s history, as it has been difficult to communicate the value of the project to an audience that is used to this false dichotomy. gVisor 并不完全符合行业内对沙箱/安全领域的传统划分,该领域通常将“原生容器”与“虚拟机”截然分开,而忽略了中间的灰色地带。gVisor 正处于这一中间地带,它提供了经验证的同等安全性,却并未勾选安全审计员、监管机构或安全从业者通常视为“安全”代名词的“虚拟化”选项。这在 gVisor 的发展史上造成了采用上的挑战,因为很难向习惯于这种错误二分法的受众传达该项目的价值。

Another challenge gVisor has faced is that of a performance perception problem. Internally within Google (and other gVisor-using companies, such as Ant Group and Modal), there exist Linux kernel patches that improve gVisor performance significantly. However, for other gVisor users, out-of-the-box performance often shows performance degradation for certain I/O-intensive workloads. This has led to poor first-impressions from potential adopters. We have tried to address this by upstreaming Linux kernel patches that improve its performance, but have been turned down by kernel maintainers due to gVisor being a wholly-owned Google project. gVisor 面临的另一个挑战是性能认知问题。在 Google 内部(以及蚂蚁集团、Modal 等其他使用 gVisor 的公司),存在能够显著提升 gVisor 性能的 Linux 内核补丁。然而,对于其他 gVisor 用户而言,开箱即用的性能在某些 I/O 密集型工作负载下往往表现不佳。这导致潜在采用者对其第一印象较差。我们曾尝试通过向上游提交改进性能的 Linux 内核补丁来解决此问题,但由于 gVisor 是 Google 全资拥有的项目,遭到了内核维护者的拒绝。

Lastly, gVisor as a project has potential that is difficult to prioritize when guided by corporate ownership alone. As a userspace implementation of Linux, gVisor has potential non-commercial applications such as: 最后,作为一个项目,gVisor 在仅由企业所有权主导时,很难优先考虑某些潜力方向。作为 Linux 的用户空间实现,gVisor 具有潜在的非商业应用场景,例如:

  • gVisor-on-Mac: Allowing Linux programs to run on macOS, with a similar experience as to how Wine allows Windows programs on macOS.
  • gVisor-on-Mac: 允许 Linux 程序在 macOS 上运行,体验类似于 Wine 在 macOS 上运行 Windows 程序的方式。
  • Desktop Linux sandboxing: Allowing gVisor to be used as a practical option for desktop Linux application sandboxing that is much more secure than the current state of the art (bubblewrap/flatpak/nsjail/etc), yet much easier to integrate with than full-blown virtualization-based approaches like that of Qubes OS. We have made some advancements on this front with our recently-introduced bwrap drop-in replacement, but gVisor is capable of sandboxing so much more.
  • 桌面 Linux 沙箱: 使 gVisor 成为桌面 Linux 应用沙箱的实用选择,它比当前最先进的技术(如 bubblewrap/flatpak/nsjail 等)更安全,且比 Qubes OS 等基于全虚拟化的方案更容易集成。我们在这一领域已取得了一些进展,推出了 bwrap 的直接替代品,但 gVisor 的沙箱能力远不止于此。

We see evidence of these problems by looking at the current set of gVisor adopters, which are all either large tech companies with the ability to invest and customize gVisor to suit their own needs (Google, Ant Group, OpenAI, Anthropic), or startups with a highly-specific focus that exactly fits gVisor’s use-case. 通过观察当前的 gVisor 采用者,我们可以看到这些问题的证据:他们要么是拥有投资和定制 gVisor 以满足自身需求能力的大型科技公司(如 Google、蚂蚁集团、OpenAI、Anthropic),要么是业务重点与 gVisor 使用场景高度契合的初创公司。

Who is not on this list? 谁不在这个名单上?

  • Hobbyist projects: See aforementioned non-commercial applications where gVisor would be useful but isn’t currently adopted.
  • 业余爱好者项目: 参见上述提到的非商业应用,gVisor 在这些领域本应有用,但目前尚未被采用。
  • The “middle” of the industry: Individuals and companies that would benefit from gVisor’s security, but either aren’t aware of its existence, dismiss it out of past perception problems, or don’t have the resources to invest specifically into security.
  • 行业“中间层”: 那些本可以从 gVisor 的安全性中受益的个人和公司,但他们要么不知道它的存在,要么因过去的性能认知问题而将其排除,要么没有资源专门投入到安全领域。
  • Other non-Google hyperscalers: While gVisor is adopted internally by nearly all large tech companies for their own at-scale sandboxing needs, only a small subset directly sell general-purpose gVisor-powered compute to their customers. This is in spite of gVisor’s competitive operational margins, as well as the demonstrable demand for this.
  • 其他非 Google 超大规模云厂商: 虽然几乎所有大型科技公司都在内部采用 gVisor 来满足其大规模沙箱需求,但只有少数几家直接向客户销售基于 gVisor 的通用计算服务。尽管 gVisor 具有极具竞争力的运营利润率,且市场需求明显,但这种情况依然存在。

The remaining explanation of the lack of direct integration is likely the project’s (pre-donation) governance risk. By contributing the project to the CNCF, we aim to address all of these issues. This enables gVisor and application kernels to become… 导致缺乏直接集成的剩余原因,很可能是该项目(捐赠前)的治理风险。通过将项目贡献给 CNCF,我们旨在解决所有这些问题。这将使 gVisor 和应用内核能够……