Google donates the gVisor sandbox to the CNCF and gives up sole control
Google is donating gVisor, its container sandbox that implements the Linux system-call interface in user space, to the Cloud Native Computing Foundation, together with the project's name and trademarks. The gVisor team announced the move on the project blog on 2 October. According to the post, the CNCF reviewed the application on 22 September and accepted it on 28 September.
The post sets out what changes and when. Over the next few weeks, gVisor's build and test infrastructure moves to GitHub Actions, and Google's internal test systems will no longer be able to block pull requests. Maintainers from outside Google will be added and given merge rights. Over the next few months, the project plans to work towards CNCF incubation, move its GitHub repository out of the google organisation, and adopt a long-term governance model with organisation-based voting, which the post says is meant to stop Google from making governance decisions on its own.
The team is unusually frank about why. gVisor, first released under the Apache 2.0 licence, does not fit the usual split between "plain containers" and "virtual machines", and because it does not tick the virtualisation box that auditors often treat as shorthand for secure, it has been hard to explain to buyers. It has also had a performance reputation problem: Google and other heavy users such as Ant Group and Modal run Linux kernel patches that speed it up considerably, but other users see slowdowns on some I/O-heavy workloads out of the box. The post says attempts to upstream those kernel patches were turned down by kernel maintainers because gVisor was a project wholly owned by Google.
The authors also list who is missing from the user base. Large companies, including Google, Ant Group, OpenAI and Anthropic, use it, as do startups whose product fits it exactly, such as Modal and Tines. Among hyperscalers, the post says, only Google, DigitalOcean and Modal sell general-purpose gVisor-backed compute, although issue reports show many people installing it themselves on other clouds. Ideas such as running Linux programs on macOS or sandboxing desktop Linux applications have been hard to prioritise under single-company ownership.

Why it matters
For teams evaluating sandboxes for untrusted code — AI agents executing code are now the obvious case — governance has been a real objection to gVisor, and the post says so. Neutral ownership may also unblock the kernel patches that decide whether gVisor is fast on a stock kernel. Both are promises for now; the concrete markers to watch are outside merge rights, the repository move and the first patch accepted upstream.