Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
kern — Rootless container runtime and sandbox that launches kernel-enforced OCI images in milliseconds with no daemon, featuring resource profiles, seccomp allowlists, and compose support for untrusted and AI-generated code. | Kitploit
도구/GitHubGitHub/getkern/kern
Cloud Infrastructure SecurityContainer SecurityDynamic Analysis (Sandboxing)Security VirtualizationDevSecOpsAI Security
GitHubgetkern/kern

kern

Rootless container runtime and sandbox that launches kernel-enforced OCI images in milliseconds with no daemon, featuring resource profiles, seccomp allowlists, and compose support for untrusted and AI-generated code.

저장소 보기
42810786일 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
웹사이트
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.
kern

CI License: Apache-2.0 Release PyPI npm Runs on

kern: a fast, rootless container runtime and sandbox with no daemon. It runs workloads, including agent tool calls and code generated by an LLM, in real containers enforced by the kernel.

A real, kernel-enforced container in a few milliseconds, out of one static binary with no daemon.

MCP support for Claude Code, Cursor, Claude Desktop and LM Studio, through Kern Sandbox.

Two windows. Container: kern box dev --image alpine -it -- sh; kern compose up -d, for your compose.yaml; kern ps. Sandbox: import kern_sandbox as kern; r = kern.run_code("print(6 * 7)"); print(r.stdout) prints 42.

0 RAM at rest · no daemon, no socket, nothing to start · one static binary, libc its only Rust dependency

# Linux. Windows and macOS below.
curl -fsSL https://raw.githubusercontent.com/getkern/kern/main/install.sh | sh

What kern is

A rootless container runtime in one static binary, with no daemon. The same binary is the sandbox an agent's code runs in, called from Python, Node or any MCP client. kern calls a container a box.

  • Real OCI images: pull, build, commit, push, save/load. A box starts in single-digit milliseconds.
  • A sandbox for code your model wrote. It runs where it can't touch your machine, with no network unless you ask.
  • Rootless, always. Six namespaces, a read-only or overlay root, a seccomp allowlist, cgroup v2 limits.
  • Your docker-compose.yml, unchanged, or kern's own stack.toml.
  • Limits without a sandbox. kern run puts the same caps on a plain process on the host. docs/RESOURCES.md
  • The tools you expect: ps, logs, exec, stats, inspect, top, doctor.

Install

Linux, x86_64 or aarch64
curl -fsSL https://raw.githubusercontent.com/getkern/kern/main/install.sh | sh
Windows, through WSL2
irm https://raw.githubusercontent.com/getkern/kern/main/install.ps1 | iex
macOS, in a Linux VM
brew install colima
colima start
colima ssh

Then, inside the VM:

curl -fsSL https://raw.githubusercontent.com/getkern/kern/main/install.sh | sh

Then kern doctor checks the host and says what to fix. Ubuntu 23.10 and newer need one root step first: docs/INSTALL.md.

Quickstart

What it doesCommand
A shell in a real OCI imagekern box dev --image alpine -it -- sh
A service, published on the hostkern box svc --image nginx:alpine -d -p 8080:80
Untrusted code, with the strict profilekern box job --image python:3.12-slim --security-profile untrusted -- python3 -c "print('hi')"
What is running (--json too)kern ps

--security-profile untrusted is the seccomp allowlist, --cap-drop ALL and --read-only in one flag. examples/ holds 94 runnable scripts, one per thing kern does.

Kern Sandbox: run an agent's code from Python or Node

python3 -m venv .venv && . .venv/bin/activate
pip install -U kern-sandbox
import kern_sandbox as kern

r = kern.run_code("print(sum(range(100)))")
print(r.stdout, r.fault)   # 4950  None

Your code runs in a container of its own, for one call or for a whole session, and a timeout or an out-of-memory comes back as a typed fault. Node: npm install kern-sandbox.

Three windows. files.py: a Sandbox writes in.csv, runs a job, reads out.txt back. state.py: a kernel keeps x = 40 between calls and prints x + 2. package.py: a Sandbox with setup pip install numpy imports numpy.

These three and three more, ready to copy: the Python SDK, the same for Node.

MCP server for Claude Code, Cursor, Claude Desktop and LM Studio. The same block goes in claude_desktop_config.json, in Cursor's or LM Studio's mcp.json, or in .mcp.json at your project root for Claude Code:

{
  "mcpServers": {
    "kern": { "command": "uvx", "args": ["--from", "kern-sandbox", "kern-mcp"] }
  }
}

Every option: docs/MCP.md.

Run a whole stack: your docker-compose.yml, unchanged

# stack.toml - one table per service, keys spelled like the `kern box` flags
[box.cache]
image = "redis:7-alpine"

[box.web]
image      = "nginx:alpine"
ports      = ["8080:80"]
depends_on = ["cache"]
kern compose stack.toml up            # start it (or point it at your compose.yaml)
kern compose stack.toml ps            # what is running, and what each service publishes
kern compose stack.toml port web 80   # the host address serving a port

Each service gets its own network namespace and they reach each other by name. It is the local dev loop, not a production orchestrator. docs/DOCKER-COMPAT.md

Speed and footprint

Terminal: 'kern box app --image alpine -- echo hello from a real container' prints the greeting, then reports that kern is 80x faster than docker run. A real OCI image, rootless, a static binary, no daemon, measured on x86 on 2026-09-20, and you should measure your own.

one isolated /bin/true                              kern is
one container, against docker run --rm80x faster
200 at once, against docker run --rm130x faster
one container, against rootless runc3.6x faster
kernDockerPodman     
Daemonnoyes (dockerd + containerd)no
Resident memory, nothing running0154 to 160 MB0
Rootlessyes, alwaysopt-inyes
도구 다운로드