nsjail by google

A lightweight process isolation tool that utilizes Linux namespaces, cgroups, rlimits and seccomp-bpf syscall filters, leveraging the Kafel BPF language for enhanced security.

updated at Nov. 16, 2024, 5:34 a.m.

C++

88 -1

2,979 +9

274 +0

GitHub
photon by vmware

Minimal Linux container host

updated at Nov. 15, 2024, 11:53 p.m.

Python

188 +0

3,049 +2

697 +1

GitHub
porto by yandex

Yet another Linux container management system

updated at Nov. 15, 2024, 9:53 p.m.

C++

44 +0

397 -1

52 +0

GitHub
bubblewrap by containers

Low-level unprivileged sandboxing tool used by Flatpak and similar projects

updated at Nov. 15, 2024, 5:23 p.m.

C

55 +0

3,966 +12

237 +0

GitHub
img by genuinetools

Standalone, daemon-less, unprivileged Dockerfile and OCI compatible container image builder.

updated at Nov. 15, 2024, 5:59 a.m.

Go

51 +0

3,908 +1

231 +0

GitHub
swarmpit by swarmpit

Lightweight mobile-friendly Docker Swarm management UI

updated at Nov. 14, 2024, 9:31 p.m.

Clojure

68 +0

3,114 +8

285 +0

GitHub
singularity by apptainer

Singularity has been renamed to Apptainer as part of us moving the project to the Linux Foundation. This repo has been persisted as a snapshot right before the changes.

updated at Nov. 14, 2024, 7:47 p.m.

Go

88 +0

2,532 +2

424 +0

GitHub
container-diff by GoogleContainerTools

container-diff: Diff your Docker containers

updated at Nov. 13, 2024, 4:18 p.m.

Go

65 +0

3,759 +1

234 +0

GitHub
cnab-spec by cnabio

Cloud Native Application Bundle Specification

updated at Nov. 12, 2024, 8:03 p.m.

Shell

51 +0

957 +1

99 +0

GitHub
Whaler by P3GLEG

Program to reverse Docker images into Dockerfiles

updated at Nov. 12, 2024, 7:31 p.m.

Go

24 +0

1,067 +2

95 +0

GitHub
rkt by rkt

[Project ended] rkt is a pod-native container engine for Linux. It is composable, secure, and built on standards.

updated at Nov. 12, 2024, 3:39 p.m.

Go

420 +0

8,822 -1

883 +0

GitHub
oci-seccomp-bpf-hook by containers

OCI hook to trace syscalls and generate a seccomp profile

updated at Nov. 12, 2024, 8:02 a.m.

Go

15 +0

303 +0

36 +0

GitHub
bane by genuinetools

Custom & better AppArmor profile generator for Docker containers.

updated at Nov. 11, 2024, 8:16 p.m.

Go

34 +0

1,183 +1

85 +0

GitHub
lxroot by parke

A lightweight, flexible, and safer alternative to chroot and/or Docker.

updated at Nov. 10, 2024, noon

C++

9 +0

100 +0

9 +0

GitHub
lmctfy by google

lmctfy is the open source version of Google’s container stack, which provides Linux application containers.

updated at Nov. 10, 2024, 2:41 a.m.

C++

247 +0

3,411 +0

237 +0

GitHub
footloose by weaveworks

Container Machines - Containers that look like Virtual Machines

updated at Nov. 9, 2024, 7:59 a.m.

Go

67 +0

1,591 +0

122 +0

GitHub
runv by hyperhq

Hypervisor-based Runtime for OCI

updated at Nov. 6, 2024, 9:52 a.m.

Go

43 +0

826 +0

129 +0

GitHub
docker-pushrm by christian-korneck

"Docker Push Readme" - a Docker CLI plugin to update container repo docs

updated at Nov. 3, 2024, 7:12 a.m.

Go

5 +0

139 +0

4 +0

GitHub
sysdig-container-ecosystem by draios

The Container Ecosystem Project

updated at Oct. 28, 2024, 10:17 p.m.

Unknown languages

32 +0

112 +0

22 +0

GitHub
vagga by tailhook

Vagga is a containerization tool without daemons

updated at Oct. 27, 2024, 12:16 p.m.

Rust

48 +0

1,864 +0

96 +0

GitHub