awesome-repositories.com
المدونة
MCP
awesome-repositories.com

اكتشف أفضل مستودعات المصادر المفتوحة باستخدام بحث مدعوم بالذكاء الاصطناعي.

استكشفعمليات بحث منسقةبدائل مفتوحة المصدربرمجيات ذاتية الاستضافةالمدونةخريطة الموقع
المشروعحولكيفية ترتيب النتائجالصحافةخادم MCP
قانونيالخصوصيةالشروط
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
youki-dev avatar

youki-dev/youki

0
View on GitHub↗
7,452 نجوم·440 تفرعات·Rust·Apache-2.0·8 مشاهداتyouki-dev.github.io/youki↗

Youki

Youki is a low-level container runtime written in Rust that creates and manages isolated containers according to Open Container Initiative specifications. It serves as an execution engine that can function as a rootless container manager or a pluggable Kubernetes CRI runtime to manage pods and containers within a cluster.

The project distinguishes itself by providing a Wasm container runtime capable of executing WebAssembly modules as isolated workloads compatible with standard orchestration tools. It further supports a rootless execution model, allowing isolated environments to start as non-root users to reduce security risks and remove the need for administrative privileges.

The runtime covers a broad range of system capabilities, including Linux sandbox provisioning, hardware resource limit configuration via cgroups, and security hardening through system call filtering. It also handles container network interface management, process execution control, and the full container lifecycle from creation to termination.

The project includes tooling for multi-architecture cross-compilation and automated provisioning of virtualized Linux environments for testing and development.

Features

  • OCI Container Engines - Implements the Open Container Initiative standards for building and running isolated containers.
  • OCI Runtime Implementations - Implements a low-level container runtime that adheres to Open Container Initiative specifications for image formats and execution.
  • Sandbox Process Execution - Runs containers and pods using compatible sandboxes to isolate processes and manage hardware resources.
  • Runtime Lifecycle Management - Manages the full container lifecycle from creation to termination by interfacing with host kernel features.
  • Container Runtime Integrations - Implements the Container Runtime Interface to allow Kubernetes to orchestrate pods and containers via the runtime.
  • Wasm Execution Engines - Provides a specialized execution environment for running WebAssembly modules as isolated containers.
  • Namespace-Based Isolation - Leverages Linux kernel namespaces to create isolated execution environments and partition system resources.
  • Linux Sandboxes - Implements Linux sandbox provisioning using kernel namespaces and cgroups to create isolated execution environments.
  • WebAssembly - Executes WebAssembly modules as isolated containers by assigning them to a dedicated runtime handler.
  • Containerized Workloads - Executes WebAssembly modules as isolated workloads that are compatible with standard container orchestration tools.
  • Wasm Sandboxes - Provides a dedicated handler to run WebAssembly modules as isolated workloads within a sandbox.
  • Rootless Container Runtimes - Provides a rootless execution model that allows containers to run without requiring administrative privileges on the host.
  • Container Security Hardening - Hardens the container environment by applying security profiles and filtering system calls.
  • Seccomp Profiles - Hardens the container sandbox by restricting available system calls through defined seccomp security profiles.
  • Kernel Resource Limiting - Uses Linux kernel control groups to enforce hardware resource limits like CPU and memory for containers.
  • Container Management Systems - Executes containerized processes by leveraging system primitives and adhering to industry-standard specifications.
  • Rust Systems Programming - Developed in Rust to ensure memory safety and performance when interfacing with low-level Linux kernel features.
  • Memory-Safe Systems Programming - Built with Rust to ensure memory safety while interfacing directly with low-level Linux kernel system calls.
  • Cgroup Resource Analyzers - Exports usage statistics and configures root paths for Linux control groups to monitor resource consumption.
  • DevOps & Infrastructure - Container runtime implementation.
  • Virtualization & Containers - Container runtime implementation.
  • Container Runtimes - Rust-based OCI-compliant container runtime.

سجل النجوم

مخطط تاريخ النجوم لـ youki-dev/youkiمخطط تاريخ النجوم لـ youki-dev/youki

بحث بالذكاء الاصطناعي

استكشف المزيد من المستودعات الرائعة

صف ما تحتاجه بلغة بسيطة — وسيقوم الذكاء الاصطناعي بترتيب آلاف المشاريع مفتوحة المصدر المنسقة حسب الصلة.

Start searching with AI

بدائل مفتوحة المصدر لـ Youki

مشاريع مفتوحة المصدر مشابهة، مرتبة حسب عدد الميزات المشتركة مع Youki.
  • containers/crunالصورة الرمزية لـ containers

    containers/crun

    3,975عرض على GitHub↗

    crun is a low-level container runtime that implements the Open Container Initiative specification for managing the lifecycle of isolated processes. It provides the core mechanisms for container creation, execution, and deletion, ensuring compatibility across platforms through standardized lifecycle management. The project distinguishes itself by offering a shared C library that allows container runtime operations to be embedded directly into other compiled applications. It further extends execution capabilities through specialized handlers that enable the deployment of containers within isola

    Ccontainersiotiot-cloud
    عرض على GitHub↗3,975
  • moby/mobyالصورة الرمزية لـ moby

    moby/moby

    71,729عرض على GitHub↗

    Moby is an OCI container engine and runtime manager designed for building, running, and managing isolated containers based on Open Container Initiative standards. It functions as a container daemon and image builder, providing a core engine to orchestrate the full lifecycle of containers and the packaging of source code into portable images. The project provides a standardized HTTP interface that allows for programmatic container management, enabling external clients to control daemon settings and container operations. It supports a rootless security model, allowing the engine daemon to execu

    Gocontainersdockergo
    عرض على GitHub↗71,729
  • containers/youkiالصورة الرمزية لـ containers

    containers/youki

    7,463عرض على GitHub↗

    Youki is an OCI container runtime written in Rust. It implements the Open Container Initiative runtime specification to manage the lifecycle of containerized processes and ensure compatibility with standard container images and engines. The runtime is designed for memory safety and supports rootless container execution, allowing containers to run as non-root users to reduce security risks and limit privilege escalation. It provides core container management capabilities, including spawning and managing OCI containers. This is achieved through Linux namespace isolation, cgroup-based resource

    Rust
    عرض على GitHub↗7,463
  • kata-containers/kata-containersالصورة الرمزية لـ kata-containers

    kata-containers/kata-containers

    8,106عرض على GitHub↗

    Kata Containers is an OCI container runtime that launches containers inside lightweight virtual machines to combine hardware-level isolation with container operational speed. It functions as a hardware-isolated container engine and lightweight VM hypervisor, providing a virtual machine monitor interface that abstracts multiple hypervisors to optimize for performance or specific hardware emulation. The project distinguishes itself through a confidential computing runtime that leverages hardware-backed trusted execution environments, such as Intel TDX and AMD SEV-SNP, to protect data in use. It

    Rustacrncontainerscri
    عرض على GitHub↗8,106
عرض جميع البدائل الـ 30 لـ Youki→

الأسئلة الشائعة

ما هي وظيفة youki-dev/youki؟

Youki is a low-level container runtime written in Rust that creates and manages isolated containers according to Open Container Initiative specifications. It serves as an execution engine that can function as a rootless container manager or a pluggable Kubernetes CRI runtime to manage pods and containers within a cluster.

ما هي الميزات الرئيسية لـ youki-dev/youki؟

الميزات الرئيسية لـ youki-dev/youki هي: OCI Container Engines, OCI Runtime Implementations, Sandbox Process Execution, Runtime Lifecycle Management, Container Runtime Integrations, Wasm Execution Engines, Namespace-Based Isolation, Linux Sandboxes.

ما هي البدائل مفتوحة المصدر لـ youki-dev/youki؟

تشمل البدائل مفتوحة المصدر لـ youki-dev/youki: containers/crun — crun is a low-level container runtime that implements the Open Container Initiative specification for managing the… moby/moby — Moby is an OCI container engine and runtime manager designed for building, running, and managing isolated containers… containers/youki — Youki is an OCI container runtime written in Rust. It implements the Open Container Initiative runtime specification… kata-containers/kata-containers — Kata Containers is an OCI container runtime that launches containers inside lightweight virtual machines to combine… ioi/isolate — Isolate is a low-level sandbox designed to execute untrusted programs within a strictly controlled environment. It… netblue30/firejail — Firejail is a Linux application sandbox and kernel security wrapper that isolates untrusted applications from the host…