Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
pumba — Chaos testing, network emulation, and stress testing tool for containers | Kitploit
Tools/GitHubGitHub/alexei-led/pumba
Container SecurityDevSecOpsChaos EngineeringTop in Chaos Engineering #8
GitHubalexei-led/pumba

pumba

Chaos testing, network emulation, and stress testing tool for containers

View Repository
3.2k221431 month agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Pumba
Chaos testing tool for Docker, containerd, and Podman

GitHub Release Release Build and Test Go Report Card Codecov License

Quick Start · User Guide · Network Chaos · Deployment · Contributing


Pumba is a chaos testing and network emulation tool for Docker, containerd, and Podman containers. Inspired by Netflix Chaos Monkey, Pumba brings chaos engineering to the container level — kill, stop, pause, and remove containers, inject network delays and packet loss, or stress-test container resources.

How It Works

graph LR
    A[Pumba CLI] -->|Docker API / containerd API / Podman compat API| B[Container Runtime]
    B -->|List & Filter| C[Target Containers]

    A -->|kill / stop / pause / rm| C

    A -->|netem / iptables| D[Helper Container / Direct Exec]
    D -->|Shares network namespace| C
    D -->|Runs tc / iptables| E[Network Chaos]

Supported runtimes

RuntimeSocket (default)netem / iptables / stressNotes
Docker/var/run/docker.sockWorks as root or with socket accessDefault runtime.
containerd/run/containerd/containerd.sockRequires root (overlayfs mounts for sidecar)Namespaces: k8s.io (Kubernetes), moby (Docker-managed), default (pure containerd).
Podman/run/podman/podman.sock (rootful)Requires rootful Podman (fails fast else)Uses Podman's Docker-compat API; on macOS pumba runs inside podman machine (see below).

Supported platforms

Pumba targets Linux containers — every chaos action depends on Linux primitives (netns, cgroups v2, iptables, tc qdiscs, container runtime sockets). Released binaries:

OSamd64arm64Notes
Linux✅✅Primary target. Run pumba on the same kernel as the targeted containers.
macOS✅✅Developer ergonomics only. Use it to drive a remote Docker/Podman/containerd VM (e.g. Colima, podman machine).
Windows❌❌Not supported and not planned. See below.

Windows is intentionally not built. The chaos primitives — Linux netns/cgroup writes, tc/iptables sidecar injection, POSIX signal forwarding (SIGCONT/SIGSTOP/SIGUSR1/SIGUSR2 used by the containerd runtime) — have no Windows equivalent. There is no plausible Windows use case even with Docker Desktop's WSL2 backend, so no Windows binary is published. PRs adding Windows support will not be accepted; please run pumba on Linux (native, container, or VM).

Features

CategoryCommandsDescription
Container Chaoskill, stop, pause, rm, restartDisrupt container lifecycle
ExecuteexecRun commands inside containers
Network Delaynetem delayAdd latency to egress traffic
Packet Lossnetem loss, iptables lossDrop packets (egress and ingress)
Network Effectsnetem duplicate, corrupt, rateDuplicate, corrupt, or rate-limit packets
Stress TestingstressCPU, memory, I/O stress via stress-ng (child cgroup or same-cgroup injection)
Targetingnames, regex (re2:), labels, --randomFlexible container selection
Scheduling--intervalRecurring chaos at fixed intervals

Quick Start

Install

Download the latest release for your platform, or use Docker:

# Binary
curl -sL https://github.com/alexei-led/pumba/releases/latest/download/pumba_linux_amd64 -o pumba
chmod +x pumba

# Docker (recommended)
docker pull ghcr.io/alexei-led/pumba:latest

First Chaos

# Kill a random container matching "test" every 30 seconds
pumba --interval=30s --random kill "re2:^test"

# Add 3 seconds network delay to mydb for 5 minutes
pumba netem --duration 5m delay --time 3000 mydb

# Drop 10% of incoming packets to myapp for 2 minutes
pumba iptables --duration 2m loss --probability 0.1 myapp

# Stress CPU of mycontainer for 60 seconds
pumba stress --duration 60s --stressors="--cpu 4 --timeout 60s" mycontainer

Containerd Runtime

# Kill a container by ID via containerd
pumba --runtime containerd --containerd-namespace k8s.io kill <container-id>

# Add network delay via containerd (requires tc in the container image)
pumba --runtime containerd --containerd-namespace moby \
  netem --duration 5m delay --time 3000 <container-id>

Podman Runtime

Pumba talks to Podman via its Docker-compat socket. --podman-socket is optional — if empty, pumba probes $CONTAINER_HOST, $PODMAN_SOCK, podman machine inspect, /run/podman/podman.sock, and $XDG_RUNTIME_DIR/podman/podman.sock in order.

# Kill a container by name via Podman (rootful socket auto-detected)
sudo pumba --runtime podman kill mycontainer
Download Tool