We're adding support to gvisor for container plugins, it's a reasonable approach for limiting the rich attack surface on linux

Who is "we"? What are "container plugins"?