ayush@sandbox:~$ whoami

Ayush Ranjan

systems engineer gVisor maintainer MTS @ Modal

I work in the layers between your code and the hardware.

$ cat about.txt

I'm a systems engineer who likes working close to the metal: kernels, filesystems, virtualization, GPUs, and the strange places where software meets hardware. Most of what I build is about running untrusted code safely, without paying for it in performance.

I'm a maintainer of gVisor, the open-source application kernel that sandboxes containers by reimplementing Linux in user space. It sandboxes untrusted code across all of Google's serverless products and GKE, and at companies like Modal, OpenAI, Anthropic and Ant Group. I spent six years on it at Google and have been contributing since 2019.

Today I'm a Member of Technical Staff at Modal, working on the container runtime for inference and training workloads.

$ git log --graph --stat --pretty=career

  1. *3f9a2c1(HEAD -> main) Join Modal San Francisconow+▌
  2. * a41c9e0Merge branch 'google': six years on gVisor6y++++++++++++
  3. | *8e1d7b4Relocate to the Bay Area2y++++
  4. | *6c0f5e2Relocate to Toronto, Canada1y++
  5. | *41b7d90Return to gVisor full time Bay Area3y++++++
  6. * |9c3e1a7Graduate: B.S. Computer Science & Mathematics
  7. | *2a8c6e3(tag: gvisor) Summer internship on gVisor, first commit3mo+
  8. *0d5b1f8Initial commit: start at UIUC4y++++++++

$ ls ~/work

A gVisor sandbox, and the parts of it I've worked on. Hover an area to light it up.
  1. vfs2 · lisafs · overlayfs · directfs

    Filesystems

    Years on gVisor's filesystem stack: the move to VFS2, LISAFS as the replacement for 9P, an in-sandbox overlay for the container's root filesystem, and directfs, which lets the sandbox reach host files without a round trip through the gofer.

    stat(2) >2× faster · fsstress 82×

  2. runsc checkpoint · runsc restore

    Checkpoint / restore

    Making snapshots of running sandboxes faster and more complete: better performance and coverage, filesystem snapshots, and GPU snapshots by integrating cuda-checkpoint into gVisor and making it fast.

    saves memory · filesystem · GPU state

  3. nvproxy

    GPU support

    Helped stand up GPU and CUDA support in gVisor with nvproxy, then grew it: graphics workloads, NVIDIA kernel driver versioning, bringing up new drivers, and testing driver compatibility.

    for inference & CUDA

  4. rdmaproxy

    RDMA

    Added RDMA support to gVisor so distributed training workloads can drive RDMA NICs from inside the sandbox.

    for multi-node training

  5. linux abi

    Linux compatibility

    Growing how much of Linux gVisor implements, subsystem by subsystem, so that more real applications run in the sandbox unmodified.

    goal unmodified binaries

  6. runsc vs. runc

    Performance

    Improved performance for a wide range of workloads running in gVisor, from build systems to language runtimes, closing the gap between sandboxed and native containers.

    goal runsc ≈ runc

  7. github.com/google/gvisor

    Open source

    Maintaining the gVisor open-source project, including reviewing 350+ pull requests.

    commits 900+ · reviews 350+

$ ls -lt ~/writing

  1. Faster filesystem access with Directfs

    How gVisor's sandbox started talking to the host filesystem directly, using file descriptors donated by the gofer and a careful set of syscall restrictions, and what that did for real workloads.

  2. Rootfs Overlay

    Why gVisor now keeps the container's writable layer in sandbox memory by default, and how a host-backed filestore keeps that compatible with Kubernetes storage limits.

  3. Improved gVisor file system performance for GKE, Cloud Run, App Engine and Cloud Functions

    The story of rolling out VFS2 and LISAFS across Google's sandboxed products: fewer RPCs per syscall, less lock contention, and performance much closer to native runc. Co-written with Fabricio Voznika.

# more posts on the way

$ ping -c 2 ayush

PING ayush (San Francisco, CA): 56 data bytes

64 bytes from github.com/ayushr2: icmp_seq=0 ttl=64 time=0.041 ms

64 bytes from linkedin.com/in/ayushr2: icmp_seq=1 ttl=64 time=0.038 ms

--- ayush ping statistics ---

2 packets transmitted, 2 packets received, 0.0% packet loss

Always happy to talk about kernels, filesystems, virtualization, or running untrusted code fast. Say hi.