██╗ ██╗███╗ ██╗██╗ ██╗██╗ ██╗ ██████╗ ██████╗ ███╗ ██╗████████╗ █████╗ ██╗███╗ ██╗███████╗██████╗ ███████╗
██║ ██║████╗ ██║██║ ██║╚██╗██╔╝ ██╔════╝██╔═══██╗████╗ ██║╚══██╔══╝██╔══██╗██║████╗ ██║██╔════╝██╔══██╗██╔════╝
██║ ██║██╔██╗ ██║██║ ██║ ╚███╔╝ ██║ ██║ ██║██╔██╗ ██║ ██║ ███████║██║██╔██╗ ██║█████╗ ██████╔╝███████╗
██║ ██║██║╚██╗██║██║ ██║ ██╔██╗ ██║ ██║ ██║██║╚██╗██║ ██║ ██╔══██║██║██║╚██╗██║██╔══╝ ██╔══██╗╚════██║
███████╗██║██║ ╚████║╚██████╔╝██╔╝ ██╗ ╚██████╗╚██████╔╝██║ ╚████║ ██║ ██║ ██║██║██║ ╚████║███████╗██║ ██║███████║
╚══════╝╚═╝╚═╝ ╚═══╝ ╚═════╝ ╚═╝ ╚═╝ ╚═════╝ ╚═════╝ ╚═╝ ╚═══╝ ╚═╝ ╚═╝ ╚═╝╚═╝╚═╝ ╚═══╝╚══════╝╚═╝ ╚═╝╚══════╝
A curated list of awesome Linux Containers frameworks, libraries and software
firecracker-microvm/firecracker
Secure and fast microVMs for serverless computing.
+132 this weekLow-level unprivileged sandboxing tool used by Flatpak and similar projects
Making Docker and Kubernetes management easy.
| # | repo | stars | 7d |
|---|---|---|---|
| 04 | containers/libpod Podman: A tool for managing OCI containers and pods. | 30,893 | +79 |
| 05 | wagoodman/dive A tool for exploring each layer in a docker image | 53,479 | +55 |
| 06 | projectatomic/skopeo Work with remote images registries - retrieving information, images, signing content | 10,530 | +45 |
| 07 | lxc/lxd Powerful system container and virtual machine manager | 4,966 | +38 |
| 08 | google/gvisor Application Kernel for Containers | 17,827 | +36 |
| 09 | projectatomic/buildah A tool that facilitates building OCI images. | 8,652 | +24 |
| 10 | opencontainers/runc CLI tool for spawning and running containers according to the OCI specification | 13,097 | +20 |
| repo | stars | 7d ↓ |
|---|---|---|
| firecracker-microvm/firecracker Secure and fast microVMs for serverless computing. | 32,804 | +132 |
| containers/libpod Podman: A tool for managing OCI containers and pods. | 30,893 | +79 |
| opencontainers/runc CLI tool for spawning and running containers according to the OCI specification | 13,097 | +20 |
| containers/youki A container runtime written in Rust | 7,263 | +18 |
| nestybox/sysbox An open-source, next-generation "runc" that empowers rootless containers to run workloads such as Systemd, Docker, Kubernetes, just like VMs. | 3,487 | +18 |
| lxc/lxc LXC - Linux Containers | 5,122 | +9 |
| indigo-dc/udocker A basic user tool to execute simple docker containers in batch or interactive systems without root privileges. | 1,704 | +2 |
| coreos/rkt [Project ended] rkt is a pod-native container engine for Linux. It is composable, secure, and built on standards. | 8,794 | +1 |
| tailhook/vagga Vagga is a containerization tool without daemons | 1,896 | +1 |
| google/lmctfy lmctfy is the open source version of Google’s container stack, which provides Linux application containers. | 3,410 | |
| oracle/railcar RailCar: Rust implementation of the Open Containers Initiative oci-runtime | 1,123 | |
| 01org/cc-oci-runtime OCI (Open Containers Initiative) compatible runtime for Intel® Architecture | 418 | |
| yandex/porto Yet another Linux container management system | 403 | |
| ihucos/plash Build and run layered root filesystems. | 387 | |
| xemul/libct Linux containers control plane | 107 | |
| weaveworks/footloose Container Machines - Containers that look like Virtual Machines | 1,587 | -1 |
| hyperhq/runv Hypervisor-based Runtime for OCI | 828 | -1 |
| p8952/bocker Docker implemented in around 100 lines of bash | 12,623 | -2 |
| repo | stars | 7d ↓ |
|---|---|---|
| wagoodman/dive A tool for exploring each layer in a docker image | 53,479 | +55 |
| projectatomic/skopeo Work with remote images registries - retrieving information, images, signing content | 10,530 | +45 |
| projectatomic/buildah A tool that facilitates building OCI images. | 8,652 | +24 |
| google/go-containerregistry Go library and CLIs for working with container registries | 3,761 | +8 |
| GoogleContainerTools/kaniko Build Container Images In Kubernetes | 15,752 | +1 |
| P3GLEG/Whaler Program to reverse Docker images into Dockerfiles | 1,185 | +1 |
| jessfraz/img Standalone, daemon-less, unprivileged Dockerfile and OCI compatible container image builder. | 3,990 | |
| GoogleCloudPlatform/container-diff container-diff: Diff your Docker containers | 3,801 | |
| blablacar/dgr Container build and runtime tool | 249 | |
| christian-korneck/docker-pushrm "Docker Push Readme" - a Docker CLI plugin to update container repo docs | 148 |
| repo | stars | 7d ↓ |
|---|---|---|
| zalando/python-nsenter Enter kernel namespaces from Python | 141 | |
| Friz-zy/pyspaces Works with Linux namespaces througth glibc with pure python | 88 | |
| moby/moby The Moby Project - a collaborative project for the container ecosystem to assemble container-based systems | 71,480 | -6 |
| repo | stars | 7d ↓ |
|---|---|---|
| portainer/portainer Making Docker and Kubernetes management easy. | 36,755 | +82 |
| swarmpit/swarmpit Lightweight mobile-friendly Docker Swarm management UI | 3,409 | +2 |
| repo | stars | 7d ↓ |
|---|---|---|
| google/gvisor Application Kernel for Containers | 17,827 | +36 |
| aelsabbahy/goss Quick and Easy server testing/validation | 5,867 | +2 |
| google/docker-explorer A tool to help forensicate offline docker acquisitions | 552 | |
| containers/oci-seccomp-bpf-hook OCI hook to trace syscalls and generate a seccomp profile | 338 | |
| OpenSCAP/container-compliance Assessing compliance of a container | 243 | |
| buildkite/sockguard A proxy for docker.sock that enforces access control and isolated privileges | 144 | |
| zuBux/drydock drydock provides a flexible way of assessing the security of your Docker daemon configuration and containers using editable audit templates | 65 | |
| docker/docker-bench-security The Docker Bench for Security is a script that checks for dozens of common best-practices around deploying Docker containers in production. | 9,598 | -1 |
| jfrazelle/bane Custom & better AppArmor profile generator for Docker containers. | 1,224 | -1 |
| repo | stars | 7d ↓ |
|---|---|---|
| projectatomic/bubblewrap Low-level unprivileged sandboxing tool used by Flatpak and similar projects | 6,000 | +87 |
| google/nsjail A lightweight process isolation tool that utilizes Linux namespaces, cgroups, rlimits and seccomp-bpf syscall filters, leveraging the Kafel BPF language for enhanced security. | 3,749 | +14 |
| singularityware/singularity Singularity has been renamed to Apptainer as part of us moving the project to the Linux Foundation. This repo has been persisted as a snapshot right before the changes. | 2,606 | +1 |
| subuser-security/subuser Run programs on linux with selectively restricted permissions. | 894 | +1 |
| parke/lxroot A lightweight, flexible, and safer alternative to chroot and/or Docker. | 116 | +1 |
| repo | stars | 7d ↓ |
|---|---|---|
| lxc/lxd Powerful system container and virtual machine manager | 4,966 | +38 |
| tailhook/lithos Process supervisor that supports linux containers | 117 | |
| marty90/multidocker Creates a system where users are forced to login in dedicated independent docker containers. | 56 |
| repo | stars | 7d ↓ |
|---|---|---|
| opencontainers/specs OCI Runtime Specification | 3,562 | +1 |
| deislabs/cnab-spec Cloud Native Application Bundle Specification | 970 | -1 |
| repo | stars | 7d ↓ |
|---|---|---|
| vmware/photon Minimal Linux container host | 3,170 | +3 |
| repo | stars | 7d ↓ |
|---|---|---|
| cloudfoundry/warden Cloud Foundry - the open platform as a service project | 284 |
| repo | stars | 7d ↓ |
|---|---|---|
| draios/sysdig-container-ecosystem The Container Ecosystem Project | 115 |