ayush@sandbox:~$ whoami
Ayush Ranjan
systems engineer gVisor maintainer MTS @ Modal
I work in the layers between your code and the hardware.
This is a real (tiny) shell. Try , or .
$ cat about.txt
I'm a systems engineer who likes working close to the metal: kernels, filesystems, virtualization, GPUs, and the strange places where software meets hardware. Most of what I build is about running untrusted code safely, without paying for it in performance.
I'm a maintainer of gVisor, the open-source application kernel that sandboxes containers by reimplementing Linux in user space. It sandboxes untrusted code across all of Google's serverless products and GKE, and at companies like Modal, OpenAI, Anthropic and Ant Group. I spent six years on it at Google and have been contributing since 2019.
Today I'm a Member of Technical Staff at Modal, working on the container runtime for inference and training workloads.
$ git log --graph --stat --pretty=career
- *3f9a2c1(HEAD -> main) Join Modal San Francisco
- * a41c9e0Merge branch 'google': six years on gVisor
- | *8e1d7b4Relocate to the Bay Area
- | *6c0f5e2Relocate to Toronto, Canada
- | *41b7d90Return to gVisor full time Bay Area
- * |9c3e1a7Graduate: B.S. Computer Science & Mathematics
- | *2a8c6e3(tag: gvisor) Summer internship on gVisor, first commit
- *0d5b1f8Initial commit: start at UIUC
$ ls ~/work
-
vfs2 · lisafs · overlayfs · directfs
Filesystems
Years on gVisor's filesystem stack: the move to VFS2, LISAFS as the replacement for 9P, an in-sandbox overlay for the container's root filesystem, and directfs, which lets the sandbox reach host files without a round trip through the gofer.
stat(2) >2× faster · fsstress 82×
-
runsc checkpoint · runsc restore
Checkpoint / restore
Making snapshots of running sandboxes faster and more complete: better performance and coverage, filesystem snapshots, and GPU snapshots by integrating
cuda-checkpointinto gVisor and making it fast.saves memory · filesystem · GPU state
-
nvproxy
GPU support
Helped stand up GPU and CUDA support in gVisor with nvproxy, then grew it: graphics workloads, NVIDIA kernel driver versioning, bringing up new drivers, and testing driver compatibility.
for inference & CUDA
-
rdmaproxy
RDMA
Added RDMA support to gVisor so distributed training workloads can drive RDMA NICs from inside the sandbox.
for multi-node training
-
linux abi
Linux compatibility
Growing how much of Linux gVisor implements, subsystem by subsystem, so that more real applications run in the sandbox unmodified.
goal unmodified binaries
-
runsc vs. runc
Performance
Improved performance for a wide range of workloads running in gVisor, from build systems to language runtimes, closing the gap between sandboxed and native containers.
goal runsc ≈ runc
-
github.com/google/gvisor
Open source
Maintaining the gVisor open-source project, including reviewing 350+ pull requests.
commits 900+ · reviews 350+
$ ls -lt ~/writing
-
Faster filesystem access with Directfs
How gVisor's sandbox started talking to the host filesystem directly, using file descriptors donated by the gofer and a careful set of syscall restrictions, and what that did for real workloads.
-
Rootfs Overlay
Why gVisor now keeps the container's writable layer in sandbox memory by default, and how a host-backed filestore keeps that compatible with Kubernetes storage limits.
-
Improved gVisor file system performance for GKE, Cloud Run, App Engine and Cloud Functions
The story of rolling out VFS2 and LISAFS across Google's sandboxed products: fewer RPCs per syscall, less lock contention, and performance much closer to native runc. Co-written with Fabricio Voznika.
# more posts on the way
$ ping -c 2 ayush
PING ayush (San Francisco, CA): 56 data bytes
64 bytes from github.com/ayushr2: icmp_seq=0 ttl=64 time=0.041 ms
64 bytes from linkedin.com/in/ayushr2: icmp_seq=1 ttl=64 time=0.038 ms
--- ayush ping statistics ---
2 packets transmitted, 2 packets received, 0.0% packet loss
Always happy to talk about kernels, filesystems, virtualization, or running untrusted code fast. Say hi.