Kata containers are the right way to go about doing sandboxing on K8s. It is very underappreciated and, timing-wise, very good. With ec2 supporting nested virtualization, my guess is there is going to be wide adoption.
I am pretty sure Apple containers on MacOS Tahoe are Kata containers
I am pretty sure Apple containers on MacOS Tahoe are Kata containers