
ansible-collection-hardening
This Ansible collection provides battle tested hardening for Linux, SSH, nginx, MySQL

This Ansible collection provides battle tested hardening for Linux, SSH, nginx, MySQL

Infrastructure as code for DNS!

Scripts to build Kali cloud images (fork of https://salsa.debian.org/cloud-team/debian-cloud-images)

Declarative KVM/QEMU VM orchestration tool using YAML compose files. Manages multi-VM stacks with cloud-init, SSH, PCI passthrough, and image…

An embeddable, portable, branchable virtual machine to safely run Agents locally.

Workload identity platform that attests running services, issues SPIFFE IDs/SVIDs, and enables mTLS and JWT authentication for Kubernetes,…

Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

eBPF-powered Linux observability with AI incident detection. AGPL-3.0 licensed.

Hardened, Azure-optimized Linux distribution built from Fedora sources with RPM packaging, supply chain security, and declarative configuration for…

Immutable Linux OS image optimized for running Incus containers and virtual machines, with UEFI Secure Boot, TPM 2.0 disk encryption, and automated…

Client for Cloudflare Tunnel enabling secure outbound-only connections to origins via Zero Trust architecture. Supports HTTP, WebSocket, SSH, and RDP…

Data pipelines for cloud config and security data. Build cloud asset inventory, CSPM, FinOps, and vulnerability management solutions. Extract from…

This puppet module provides numerous security-related configurations, providing all-round base protection.

Secure and fast microVMs for serverless computing.

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

An open-source, next-generation "runc" that empowers rootless containers to run workloads such as Systemd, Docker, Kubernetes, just like VMs.

This chef cookbook provides secure ssh-client and ssh-server configurations.

Policy-driven, layered isolation and containment