
kata-containers
Secure OCI container runtime that runs workloads inside lightweight VMs, providing strong isolation across Kubernetes, containerd, and CRI-O with…

Secure OCI container runtime that runs workloads inside lightweight VMs, providing strong isolation across Kubernetes, containerd, and CRI-O with…

Rootless container runtime and sandbox that launches kernel-enforced OCI images in milliseconds with no daemon, featuring resource profiles, seccomp…

JIT-based userspace Linux kernel that runs containers natively on Apple Silicon macOS without a VM. Drop-in Docker Engine API replacement with…

Multi-distribution Linux environment manager for Android using ADB/Shizuku integration. Run Arch, Kali, Debian, Ubuntu, and more in isolated proot…

Run Windows inside a Docker container with KVM acceleration, automatic installation, and customizable resources. Supports multiple Windows versions,…

Linux application sandboxing and distribution framework

Immutable Linux OS image optimized for running Incus containers and virtual machines, with UEFI Secure Boot, TPM 2.0 disk encryption, and automated…

A rootless Android app that boots Alpine Linux: run containers (Podman/Docker/LXC) and GUI desktop apps.

Run Firefox in a rootless Podman container with dropped capabilities, isolated networking, and ephemeral storage to contain sandbox escapes and…

Linux namespaces and seccomp-bpf sandbox

Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

A security-focused library OS supporting kernel- and user-mode execution

Framework for compiling and executing Go applications on bare metal processors, enabling secure firmware development with reduced attack surface…

Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

Declarative KVM/QEMU VM orchestration tool using YAML compose files. Manages multi-VM stacks with cloud-init, SSH, PCI passthrough, and image…

Lightweight, secure Linux sandboxes for untrusted processes. Runs in the browser and on the server.

Secure and fast microVMs for serverless computing.

Cross-platform firmware development environment implementing UEFI and PI specifications. Provides build tools, cryptographic libraries, and virtual…