Choose the Right Tenant Containment Strategy for an Edge Platform
Overview
What this challenge is about.
Compare gVisor, Firecracker, and Wasmtime for an edge platform, defend your containment choice, and earn a verifiable certificate.
The scenario
The platform is a globally distributed edge-compute provider (de-identified, roughly 90 employees, about 300 points of presence) whose entire business is safely executing other companies' untrusted JavaScript and WebAssembly close to end users. Containment is not a feature here — it is the product, because a single tenant escaping its sandbox would put every neighboring tenant on that host at risk.
The Brief
What you'll do, and what you'll demonstrate.
Determine which OS-level containment strategy — or hybrid mapping of strategies to workloads — the platform should adopt to safely and economically run untrusted multi-tenant code at the edge.
Earning criteria — what you'll demonstrate
- Compare user-space-kernel, microVM, and WebAssembly isolation models in terms of their security boundary and performance cost.
- Design a fair, reproducible benchmark that holds hardware and workload constant across competing runtimes.
- Reason about blast radius: what an attacker actually reaches after escaping each kind of sandbox.
- Translate quantitative benchmark evidence into a workload-aware recommendation for a decision-maker.
- Communicate a security-versus-cost trade-off clearly to a non-specialist audience.
Program Fit
Where this fits in your program.
Sharpens the same skills your degree expects you to demonstrate.
Aligned coursework coming soon.
Skills
Skills you'll demonstrate.
Each one shows up on your verified credential.
- Containment
Apply containment to solve real industry problems and demonstrate production-level capability.
- Virtualization
Apply virtualization to solve real industry problems and demonstrate production-level capability.
- Wasm
Apply wasm to solve real industry problems and demonstrate production-level capability.
- Benchmarking
Apply benchmarking to solve real industry problems and demonstrate production-level capability.
- Os Security
Apply os security to solve real industry problems and demonstrate production-level capability.
- Operating Systems
Apply operating systems to solve real industry problems and demonstrate production-level capability.
Careers
Career paths this challenge builds toward
Completing this challenge demonstrates skills that transfer directly to these roles:
Platform Engineer
Mirrors the core platform-engineering judgment call of selecting isolation infrastructure for untrusted multi-tenant workloads, balancing security boundary, cost, and density, then defending the choice to leadership with reproducible evidence.
This challenge sharpens
- containment
- virtualization
- operating-systems
Infrastructure Security Engineer
Builds the habit of reasoning about real blast radius — what an attacker reaches after a sandbox escape — and grounding each isolation claim in documented threat models rather than assumptions, which is the daily work of securing shared infrastructure.
This challenge sharpens
- os-security
- containment
- operating-systems
WebAssembly Runtime Engineer
Develops fluency in where WebAssembly sandboxing wins and where it falls short against microVMs and user-space kernels, and how to benchmark a WebAssembly runtime fairly against heavier isolation options for production edge workloads.
This challenge sharpens
- wasm
- benchmarking
- virtualization