Containers
127 items from friz-zy/awesome-linux-containers ★2,105
-
-
-
-
gvisor github.com
gVisor is a user-space kernel, written in Go, that implements a substantial portion of the Linux system surface. It includes an Open Container Initiative (OCI) runtime called runsc that provides an isolation boundary between the application and the host kernel. The runsc…
-
Docker bench security github.com
The Docker Bench for Security is a script that checks for dozens of common best-practices around deploying Docker containers in production.
-
firecracker github.com
Firecracker runs workloads in lightweight virtual machines, called microVMs, which combine the security and isolation properties provided by hardware virtualization technology with the speed and flexibility of containers.
-
-
runc github.com
runc is a CLI tool for spawning and running containers according to the OCS specification.
-
-
LXC github.com
LXC is the well known set of tools, templates, library and language bindings. It's pretty low level, very flexible and covers just about every containment feature supported by the upstream kernel.
-
-
kaniko github.com
Kaniko is a tool to build container images from a Dockerfile, inside a container or Kubernetes cluster.
-
-
skopeo github.com
Work with remote images registries - retrieving information, images, signing content.
-
-
Bubblewrap github.com
Run applications in a sandbox using Linux namespaces without root privileges, with user namespacing provided via setuid binary.
-
Rocket github.com
rkt (pronounced "rock-it") is a CLI for running app containers on Linux. rkt is designed to be composable, secure, and fast. Based on AppC specification.
-
Vagga github.com
Vagga is a fully-userspace container engine inspired by Vagrant and Docker, specialized for development environments.
-
-
udocker github.com
A basic user tool to execute simple containers in batch or interactive systems without root privileges.
-
-
-
Whaler github.com
Whaler is designed to reverse engineer a Docker Image into the Dockerfile that created it.
-
NsJail github.com
NsJail is a process isolation tool for Linux. It makes use of the namespacing, resource control, and seccomp-bpf syscall filter subsystems of the Linux kernel.
-
img github.com
Standalone, daemon-less, unprivileged Dockerfile and OCI compatible container image builder.
-
sysbox github.com
Sysbox is a "runc" that creates secure (rootless) containers / pods that run not just microservices, but most workloads that run in VMs (e.g., systemd, Docker, and Kubernetes), seamlessly.
-
-
-
Open Container Specifications github.com
This project is where the Open Container Initiative Specifications are written. This is a work in progress.
-
Let Me Contain That For You github.com
LMCTFY is the open source version of Google’s container stack, which provides Linux application containers.
- next page of items loading…