Safety & Security · Infrastructure resource

Shared-Kernel Container Sandbox

Infrastructure resourceSafety & SecuritySafety, Security & Governancearc:SharedKernelContainerSandbox

An execution sandbox built from a standard container using kernel namespaces and cgroups, sharing the host kernel with co-located containers.

Responsibility. Provides lightweight process, filesystem and network isolation for low-risk workloads.

Also known as: Standard container, Docker container sandbox

Variant of Execution Sandbox abstract

When to choose. Choose for low-risk development environments running trusted code; insufficient for multi-tenant, sensitive-data or autonomous production workloads because of shared-kernel escape risk.

specializesis target of alternativeTois target of alternativeToalternative toExecution Sandbox: specializesExecution SandboxDedicated Hardware Sandbox: is target of alternativeToDedicated Hardware SandboxMicroVM Sandbox: is target of alternativeToMicroVM SandboxSyscall-Interception Sandbox: alternative toSyscall-Interception San…
Direct neighbourhood (hover for relationship types)

Relationships

alternative to variability

Design guidance

Quantitative guidance

As stated by the sources; verify before use.

Classification

Technologies
Dockercontainerdrunc

Sources

  1. Ch9.3: T. Nguyen, "Sandboxing and Transparency Foundations," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.3. ISBN: 9798244538229.