agentmoat moves Kubernetes workloads from the default runc runtime to gVisor (runsc), the user-space kernel that defends against the kernel-exploit step of a container-escape chain.
-
Updated
May 23, 2026 - Go
agentmoat moves Kubernetes workloads from the default runc runtime to gVisor (runsc), the user-space kernel that defends against the kernel-exploit step of a container-escape chain.
Add a description, image, and links to the workload-is topic page so that developers can more easily learn about it.
To associate your repository with the workload-is topic, visit your repo's landing page and select "manage topics."