Below-the-host-kernel isolation: a container-native Type-1 hypervisor (Xen, Rust-hardened) that gives every agent workload its own guest kernel inside a lightweight "zone." edera.dev · krata