google / nsjailLinks
A lightweight process isolation tool that utilizes Linux namespaces, cgroups, rlimits and seccomp-bpf syscall filters, leveraging the Kafel BPF language for enhanced security.
☆3,478Updated 4 months ago
Alternatives and similar repositories for nsjail
Users that are interested in nsjail are comparing it to the libraries listed below
Sorting:
- Low-level unprivileged sandboxing tool used by Flatpak and similar projects☆4,615Updated last month
- Record and Replay Framework☆10,111Updated 2 weeks ago
- Checkpoint/Restore tool☆3,367Updated last week
- Linux system exploration and troubleshooting tool with first class support for containers☆8,094Updated 6 months ago
- Ignite a Firecracker microVM☆3,512Updated last year
- syzkaller is an unsupervised coverage-guided kernel fuzzer☆5,808Updated this week
- Painless relocation of Linux binaries–and all of their dependencies–without containers.☆2,999Updated last year
- A Virtual Machine Monitor for modern Cloud workloads. Features include CPU, memory and device hotplug, support for running Windows and Li…☆4,743Updated last week
- Fully static, unprivileged, self-contained, containers as executable binaries.☆2,518Updated 6 years ago
- A kernel designed to run one and only one application in a virtualized environment☆2,952Updated last week
- A userspace out-of-memory killer☆1,969Updated 2 weeks ago
- Wrangling Untrusted File Formats Safely☆4,619Updated last month
- Application Kernel for Containers☆16,956Updated this week
- Content-Addressable Data Synchronization Tool☆1,535Updated last year
- A foreign function interface for bash.☆2,145Updated last year
- firecracker-containerd enables containerd to manage containers as Firecracker microVMs☆2,490Updated 2 weeks ago
- A linux-based assembly REPL for x86, amd64, armv7, and armv8☆1,234Updated last year
- Security oriented software fuzzer. Supports evolutionary, feedback-driven fuzzing based on code coverage (SW and HW based)☆3,247Updated this week
- Embeddable, replicated and fault-tolerant SQL engine.☆4,147Updated this week
- like ~~grep~~ UBER, but for binaries☆1,748Updated 2 years ago
- OSv, a new operating system for the cloud.☆4,200Updated last week
- Fast, indexed regexp search over large file trees☆3,859Updated 3 months ago
- A fast and lightweight fully featured OCI runtime and C library for running containers☆3,554Updated this week
- Linux namespaces and seccomp-bpf sandbox☆6,563Updated last week
- Powerful system container and virtual machine manager☆4,583Updated this week
- A transparent, highly scalable and cryptographically verifiable data store.☆3,643Updated last week
- Userspace WireGuard® Implementation in Rust☆6,552Updated 3 weeks ago
- The Unikernel & MicroVM Compilation and Deployment Platform☆2,771Updated 2 years ago
- Portable file system cache diagnostics and control☆1,886Updated last year
- High-level tracing language for Linux☆9,589Updated this week