gvisor

gvisor is Google's application kernel for containers in Go, providing a userspace TCP/IP stack (netstack) usable without kernel networking interfaces or root privileges
go, security, networking, containers