Awesome Cloud Native
Section: Runtimes & Platforms · Sandboxed Container Runtime.
Entry
Appears in 7 awesome lists
gVisor is a user-space kernel, written in Go, that implements a substantial portion of the Linux system surface. It includes an Open Container Initiative (OCI) runtime called runsc that provides an isolation boundary between the application and the host kernel. The runsc runtime integrates with…
Section: Runtimes & Platforms · Sandboxed Container Runtime.
Section: Cloud platform security · Application kernel, written in Go, that implements a substantial portion of the Linux system surface to provide an isolation boundary between the application and the host kernel.
Section: 云平台安全 · 用Go编写的应用程序内核,它实现Linux系统表面的很大一部分,用以在应用程序和主机内核之间提供隔离边界
Section: Engine & Runtime · Application Kernel for Containers.
Section: Go & Google 出品库
Section: Tools · gVisor is a user-space kernel, written in Go, that implements a substantial portion of the Linux system surface. It includes an Open Container Initiative (OCI) runtime called runsc that provides an isolation boundary between the application and the host kernel. The runsc runtime integrates with…
Section: Other · Application Kernel for Containers
The Moby Project - a collaborative project for the container ecosystem to assemble container-based systems
Docker-compatible container CLI for macOS, built on Apple's Containerization framework. Open source (AGPL-3.0), Swift.
Secure container runtime with lightweight virtual machines that feel and perform like containers, but provide stronger workload isolation using hardware virtualization technology as a second layer of defense.
is an open platform to connect, manage, and secure microservices. Istio's control plane provides an abstraction layer over the underlying cluster management platform, such as Kubernetes and Mesos.
Behavioral activity monitor designed to detect anomalous activity in containerized applications, hosts, and network packet flows by auditing the Linux kernel and enriched by runtime data such as Kubernetes metrics.
(label: exp/beginner) Industry-standard container runtime with an emphasis on simplicity, robustness and portability.
Self-hosted sandbox runtime for AI agents with isolated Docker containers, cgroup v2 memory management, and dynamic pressure monitoring.
Open Container Initiative-based implementation of Kubernetes Container Runtime Interface.