> Would gvisor + Firecracker + credential-injecting proxy + real network isolation solve this problem?
Yeah, basically. I mean I'm handwaving but yes, some combination of those would have made the attack way too expensive.