
firecracker
Secure and fast microVMs for serverless computing.

Secure and fast microVMs for serverless computing.

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Policy-driven, layered isolation and containment

Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel…

Write tests against structured configuration data using the Open Policy Agent Rego query language

An embeddable, portable, branchable virtual machine to safely run Agents locally.

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Rootless container runtime and sandbox that launches kernel-enforced OCI images in milliseconds with no daemon, featuring resource profiles, seccomp…

Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

Competition Infrastructure Management

Multi-cloud security auditing tool that leverages cloud provider APIs to gather configuration data, assess security posture, and generate HTML…

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

Security risk analysis for Kubernetes resources

OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure

Declarative KVM/QEMU VM orchestration tool using YAML compose files. Manages multi-VM stacks with cloud-init, SSH, PCI passthrough, and image…

Immutable Linux OS image optimized for running Incus containers and virtual machines, with UEFI Secure Boot, TPM 2.0 disk encryption, and automated…

ArmourBird CSF - Container Security Framework

Recovery notes for proxmox advisory ID: PSA-2026-00043-1 (CVE-2023-54391)