Skip to content

Entry

gVisor

Appears in 7 awesome lists

gVisor is a user-space kernel, written in Go, that implements a substantial portion of the Linux system surface. It includes an Open Container Initiative (OCI) runtime called runsc that provides an isolation boundary between the application and the host kernel. The runsc runtime integrates with…

Open github.comgoogle/gvisor

Found in these lists

Awesome Cloud Native

Section: Runtimes & Platforms · Sandboxed Container Runtime.

FreshScore 87

Awesome Cybersecurity Blue Team

Section: Cloud platform security · Application kernel, written in Go, that implements a substantial portion of the Linux system surface to provide an isolation boundary between the application and the host kernel.

StaleScore 53

Awesome Cybersecurity Blue Team - CN

Section: 云平台安全 · 用Go编写的应用程序内核,它实现Linux系统表面的很大一部分,用以在应用程序和主机内核之间提供隔离边界

StaleScore 47

Awesome Docker

Section: Engine & Runtime · Application Kernel for Containers.

FreshScore 92

Go资源精选中文版

Section: Go & Google 出品库

StaleScore 50

Awesome Linux Containers

Section: Tools · gVisor is a user-space kernel, written in Go, that implements a substantial portion of the Linux system surface. It includes an Open Container Initiative (OCI) runtime called runsc that provides an isolation boundary between the application and the host kernel. The runsc runtime integrates with…

StaleScore 52

awesome-go

Section: Other · Application Kernel for Containers

FreshScore 81

Moby

The Moby Project - a collaborative project for the container ecosystem to assemble container-based systems

In 9 listsDetails

Mocker

Docker-compatible container CLI for macOS, built on Apple's Containerization framework. Open source (AGPL-3.0), Swift.

In 8 listsDetails

Kata Containers

Secure container runtime with lightweight virtual machines that feel and perform like containers, but provide stronger workload isolation using hardware virtualization technology as a second layer of defense.

In 5 listsDetails

Istio

is an open platform to connect, manage, and secure microservices. Istio's control plane provides an abstraction layer over the underlying cluster management platform, such as Kubernetes and Mesos.

In 5 listsDetails

Falco

Behavioral activity monitor designed to detect anomalous activity in containerized applications, hosts, and network packet flows by auditing the Linux kernel and enriched by runtime data such as Kubernetes metrics.

In 5 listsDetails

containerd

(label: exp/beginner) Industry-standard container runtime with an emphasis on simplicity, robustness and portability.

In 4 listsDetails

Den

Self-hosted sandbox runtime for AI agents with isolated Docker containers, cgroup v2 memory management, and dynamic pressure monitoring.

In 3 lists

cri-o

Open Container Initiative-based implementation of Kubernetes Container Runtime Interface.

In 3 lists