Skip to contentSkip to content
Verified credentials. On-chain. Forever.Learn more
Ewance
Sign in
Cover image for Choose the Right Tenant Containment Strategy for an Edge Platform
Analysis

Choose the Right Tenant Containment Strategy for an Edge Platform

FreeVerified credential2 weeksAdvanced

Overview

What this challenge is about.

Compare gVisor, Firecracker, and Wasmtime for an edge platform, defend your containment choice, and earn a verifiable certificate.

The scenario

The platform is a globally distributed edge-compute provider (de-identified, roughly 90 employees, about 300 points of presence) whose entire business is safely executing other companies' untrusted JavaScript and WebAssembly close to end users. Containment is not a feature here — it is the product, because a single tenant escaping its sandbox would put every neighboring tenant on that host at risk.

CredentialBlockchain-anchored
ShareableLinkedIn-ready
LanguageEnglish
PaceSelf-paced

The Brief

What you'll do, and what you'll demonstrate.

Determine which OS-level containment strategy — or hybrid mapping of strategies to workloads — the platform should adopt to safely and economically run untrusted multi-tenant code at the edge.

Earning criteria — what you'll demonstrate

  • Compare user-space-kernel, microVM, and WebAssembly isolation models in terms of their security boundary and performance cost.
  • Design a fair, reproducible benchmark that holds hardware and workload constant across competing runtimes.
  • Reason about blast radius: what an attacker actually reaches after escaping each kind of sandbox.
  • Translate quantitative benchmark evidence into a workload-aware recommendation for a decision-maker.
  • Communicate a security-versus-cost trade-off clearly to a non-specialist audience.

Program Fit

Where this fits in your program.

Sharpens the same skills your degree expects you to demonstrate.

Aligned coursework coming soon.

Careers

Career paths this challenge builds toward

Completing this challenge demonstrates skills that transfer directly to these roles:

Platform Engineer

Mirrors the core platform-engineering judgment call of selecting isolation infrastructure for untrusted multi-tenant workloads, balancing security boundary, cost, and density, then defending the choice to leadership with reproducible evidence.

This challenge sharpens

  • containment
  • virtualization
  • operating-systems

Infrastructure Security Engineer

Builds the habit of reasoning about real blast radius — what an attacker reaches after a sandbox escape — and grounding each isolation claim in documented threat models rather than assumptions, which is the daily work of securing shared infrastructure.

This challenge sharpens

  • os-security
  • containment
  • operating-systems

WebAssembly Runtime Engineer

Develops fluency in where WebAssembly sandboxing wins and where it falls short against microVMs and user-space kernels, and how to benchmark a WebAssembly runtime fairly against heavier isolation options for production edge workloads.

This challenge sharpens

  • wasm
  • benchmarking
  • virtualization

One more thing

You can put a credential on your CV by Friday.

Choose the Right Tenant Containment Strategy for an Edge Platform