BetaPrivate beta is open. Teams are onboarded in stages.

Blog

Containers vs microVMs for AI agents

How containers, gVisor, and Firecracker microVMs isolate untrusted agent code, and how to choose between them.

Dock team · · 6 min read

An AI agent with a shell is running code you did not write and cannot fully predict. Where that code runs, and what separates it from everything else, is the most important infrastructure decision you make.

Plain containers share the host kernel

A container is a set of Linux namespaces and cgroups around a process. It is fast and cheap, but every container on a host talks to the same kernel. A kernel bug, a misconfigured capability, or a privileged mount can turn a container escape into host access.

For trusted workloads that is an acceptable trade. For an agent that can be prompt-injected into running anything, it is a thin wall.

gVisor puts a kernel in between

gVisor runs containers on top of a user-space kernel that intercepts system calls. The untrusted process never talks to the host kernel directly, which removes much of the shared-kernel risk while keeping container-like density and startup.

The cost is compatibility and speed on syscall-heavy work. Builds and tools that hammer the filesystem can run noticeably slower than on a full VM.

Firecracker microVMs give each workload its own kernel

Firecracker is a minimal virtual machine monitor built on KVM. Each microVM has its own guest kernel and a tiny device model, so the boundary between workloads is hardware virtualization. Inside, the agent can have real root, run systemd, and start Docker.

MicroVMs cost more memory and a little more startup than containers, and they need bare-metal or nested virtualization hosts.

How Dock uses both

Dock offers both, as tiers you pick per dock. Standard and Premium docks are Firecracker microVMs on KVM bare metal: the default for real development work and anything production depends on. Nano docks run as gVisor containers on shared capacity: the lowest price for batch-friendly work, with best-effort performance.

Either way, the guardrails sit outside the guest. Network policy, credential brokering, and the audit trail are enforced on the host, so root inside the dock does not reach them.

Tell us what your agents need to run.

Private beta is open. Describe your workload and we will reply about access.