1. Sshockerssh + reverse sshfs + port forwarder, in Docker-like CLI
2. aspectgoAspect-Oriented Programming framework for Go
5. buildkit-nixNix derivations as Dockerfiles (`docker build -f default.nix .`)
6. instance-per-podCreate a dedicated IaaS instance per Pod to mitigate container breakout (including CPU vulnerabilities depending on the instance type)
7. filegraintransport-agnostic, fine-grained content-addressable container image layout