Safety & Security · Infrastructure resource
Shared-Kernel Container Sandbox
Infrastructure resourceSafety & SecuritySafety, Security & Governancearc:SharedKernelContainerSandbox
An execution sandbox built from a standard container using kernel namespaces and cgroups, sharing the host kernel with co-located containers.
Responsibility. Provides lightweight process, filesystem and network isolation for low-risk workloads.
Also known as: Standard container, Docker container sandbox
Variant of Execution Sandbox abstract
When to choose. Choose for low-risk development environments running trusted code; insufficient for multi-tenant, sensitive-data or autonomous production workloads because of shared-kernel escape risk.
Relationships
alternative to variability
Design guidance
- MUST NOT be relied on as adequate isolation for high-risk, multi-tenant production deployments.
Quantitative guidance
As stated by the sources; verify before use.
- CVE-2025-23266 (NVIDIAScape) enabled container escape to host root with three lines of Dockerfile (Ch9.3).
Classification
- Technologies
- Dockercontainerdrunc
Sources
- Ch9.3: T. Nguyen, "Sandboxing and Transparency Foundations," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.3. ISBN: 9798244538229.