22 repositorios
Software that abstracts physical network hardware to create and manage isolated virtual network environments.
Explore 22 awesome GitHub repositories matching devops & infrastructure · Network Virtualization Tools. Refine with filters or upvote what's useful.
Este proyecto es un directorio integral curado por la comunidad que organiza un vasto panorama de bibliotecas, frameworks y herramientas de software de Python. Sirve como una base de conocimientos centralizada diseñada para facilitar la navegación del ecosistema y acelerar el descubrimiento de desarrolladores en todo el ciclo de vida del desarrollo de software. El directorio se distingue por proporcionar un índice estructurado de recursos categorizados por dominio técnico, que van desde utilidades de desarrollo fundamentales hasta campos de ingeniería especializados. Cubre capacidades de alto nivel que incluyen inteligencia artificial, ciencia de datos, desarrollo web y gestión de infraestructura, lo que permite a los desarrolladores identificar soluciones verificadas para desafíos técnicos específicos. El proyecto abarca una amplia superficie de capacidades, incluyendo herramientas para la gestión de dependencias, análisis de código estático y pruebas automatizadas. También cataloga recursos para el almacenamiento de datos persistentes, orquestación de infraestructura en la nube y desarrollo de interfaces, proporcionando una referencia unificada para construir y mantener sistemas de software complejos.
Emulate complex network topologies and manage software-defined configurations for testing virtualized environments.
This project is an administrative reference for Docker, providing guides and command references for system maintenance, image building, network configuration, and security hardening. It serves as a comprehensive manual for managing the container lifecycle and performing general system administration. The reference covers the construction and optimization of images through build files, layering strategies, and registry integration. It also provides instructions for configuring isolated virtual networks, mapping ports, and implementing security hardening using Linux capabilities and read-only f
Guides the creation and management of isolated virtual networks to enable secure communication and service discovery.
Lima is a virtualization engine designed to provision and manage lightweight Linux, macOS, and FreeBSD virtual machines. It functions as a comprehensive virtual machine manager that leverages native hypervisors and system emulation to provide isolated environments for container development, cross-architecture testing, and secure sandboxing. The project distinguishes itself through its template-driven provisioning system, which allows users to define and automate environment configurations via local files or remote URL schemes. It integrates deeply with host systems by providing automated file
Creates, deletes, and lists isolated network segments for virtual machines to control connectivity.
WSABuilds is a management framework designed to deploy and customize virtualized mobile runtime environments on desktop operating systems. It provides a comprehensive suite of tools for building, installing, and maintaining these environments, enabling the native execution of mobile applications alongside standard desktop software. The project distinguishes itself through its focus on deep system integration and lifecycle management. It allows users to generate tailored virtual environment packages by injecting administrative tools, service components, and specific configurations prior to dep
Resolves connectivity issues by identifying and removing conflicting virtual network adapters that disrupt internet access.
EasyTier is a decentralized peer-to-peer virtual private network and mesh networking tool. It functions as a layer 3 network overlay that establishes secure tunnels between devices without requiring a centralized server or coordinator. It also serves as a WireGuard-compatible VPN, capable of acting as a server for standard WireGuard clients. The project distinguishes itself through multipath latency-based routing and the use of KCP or QUIC proxies to mitigate packet loss and stabilize connections in high-loss environments. It provides a virtual networking manager featuring a web management co
Provides a comprehensive management suite featuring a web console, GUI, and RPC API for network configuration.
Flare-VM es un entorno de análisis de malware para Windows que consiste en scripts de instalación que automatizan el aprovisionamiento de una máquina virtual. Proporciona un conjunto integral de herramientas de ingeniería inversa, incluyendo descompiladores y depuradores, junto con las configuraciones del sistema y variables de entorno necesarias para la investigación de seguridad. El proyecto funciona como un orquestador de imágenes de máquinas virtuales, permitiendo la creación, gestión y exportación automatizadas de dispositivos de análisis especializados. Cuenta con selección de herramientas basada en configuración y la capacidad de extender la lógica de instalación mediante modificaciones personalizadas del registro y definiciones de diseño del sistema. El sistema incluye capacidades para la configuración de red aislada para evitar la comunicación externa mediante el modo host-only. También gestiona el ciclo de vida completo de los estados de análisis mediante la gestión de estados basada en instantáneas, incluida la capacidad de limpiar o exportar instantáneas como archivos de dispositivo verificados.
Recursively deletes VM snapshots and their children to remove old analysis states and reclaim storage space.
dockerlabs is a collection of educational labs and technical tutorials designed to teach the fundamentals of containerization and microservice architecture. It provides instructional material and hands-on exercises covering image optimization, security training, infrastructure setup, and cluster orchestration. The project features specific courses and guides focused on reducing image size through multi-stage builds, securing workloads via vulnerability scanning and encrypted networks, and deploying multi-node clusters with high availability using Swarm orchestration. The materials cover a br
Covers attaching containers to specific network drivers to manage service communication and isolation.
Firejail is a Linux application sandbox and kernel security wrapper that isolates untrusted applications from the host system. It uses kernel namespaces and seccomp filters to restrict filesystem access, drop kernel capabilities, and limit the system attack surface. The project is distinguished by its use of predefined security profiles to automatically apply filesystem restrictions and syscall limits based on the executable being launched. It provides specialized isolation for portable packages such as AppImages and implements X11 display isolation via proxy servers to prevent keyboard loggi
Initializes a separate TCP/IP stack with its own routing table and firewall for traffic isolation.
n2n is a peer-to-peer VPN that creates an encrypted mesh network by establishing layer 2 overlay networks. It uses UDP tunneling to connect remote computers into a shared virtual local area network, allowing devices to communicate as if they were on the same physical Ethernet switch. The system utilizes a centralized signaling registry and federated coordination nodes to facilitate peer discovery and node registration. It implements NAT traversal through UDP hole punching and UPnP port mapping, while using supernode relay routing to ensure connectivity when symmetric NATs prevent direct peer-
Creates a virtual Ethernet segment allowing remote devices to communicate as if on the same physical switch.
Weave is a multi-host container networking tool that connects containers running on different physical machines into a single virtual network. It creates a software-defined overlay network spanning multiple hosts, enabling containers to communicate directly with each other as if they were on the same local switch. The system provides automatic service discovery, resolving container names to network addresses across hosts without manual configuration. Traffic between containers on different hosts is secured through encrypted tunnels, preventing eavesdropping and tampering. Weave also includes
Attaches containers to a virtual Ethernet bridge for direct L2 connectivity across hosts.
Microsandbox is a runtime for creating and managing lightweight, hardware-isolated virtual machines — called sandboxes — that boot directly from standard OCI container images. Each sandbox runs as its own host process with a separate kernel, filesystem, and network stack, providing process-per-sandbox isolation. The project includes a command-line tool and multi-language SDKs (Rust, TypeScript, Python, Go) for programmatic lifecycle control, and it communicates with sandbox agents over Unix sockets using a CBOR-encoded protocol. What distinguishes Microsandbox is its combination of host-manag
Deletes sandboxes and their persisted state, with optional force-stop before removal.
Attaches network interfaces into container network namespaces by executing plugins.
Mininet is a network emulator that creates virtual networks of hosts, switches, and links on a single Linux machine for Software-Defined Networking (SDN) prototyping and testing. It emulates network nodes as lightweight processes in isolated network namespaces, connecting them via virtual Ethernet pairs, and supports OpenFlow protocol for programmable control of virtual switches and traffic flows. The project enables users to design custom network topologies using a Python API, simulate link conditions such as bandwidth, delay, and packet loss, and run real Linux applications and kernel code
Emulates entire network nodes as lightweight processes in isolated namespaces, the core architecture of the emulator.
Bubblewrap is a Linux sandbox runner that creates lightweight, isolated execution environments for running untrusted applications. It combines Linux user, mount, network, PID, and UTS namespaces with seccomp-BPF system call filtering to restrict filesystem, network, process, and inter-process communication access. The project provides comprehensive process isolation by giving each sandbox its own private tmpfs root with selective bind-mounts, a separate network stack containing only a loopback interface, an independent process ID space, and remapped user and group identifiers. It applies secc
Gives the sandbox its own network namespace with only a loopback interface, blocking external access.
CRI-O is an open-source container runtime that implements the Kubernetes Container Runtime Interface (CRI) to manage container images, pods, and containers on cluster nodes using OCI-compatible runtimes. It serves as a node-level container manager that handles image pulling, container lifecycle, and resource monitoring for Kubernetes clusters, running containers according to the Open Container Initiative specifications. The runtime distinguishes itself through live configuration reloading that applies changes to runtime definitions, registry mirrors, and TLS certificates without restarting th
Removes network namespace entries such as veth pairs when a sandbox is removed.
LXD is a unified platform for managing both system containers and virtual machines through a single REST API and command-line interface. It provides a programmatic HTTP interface for controlling the full lifecycle of instances, enabling automation and integration with external tools. The system runs unprivileged containers with per-instance UID/GID mappings, seccomp filters, and AppArmor profiles for kernel-level isolation, while supporting multiple storage backends including directory, Btrfs, LVM, ZFS, Ceph, LINSTOR, and TrueNAS through a unified driver interface. The platform distinguishes
Creates virtual device pairs to connect instances to a host bridge for shared network access.
Incus is a unified orchestration platform for managing system containers, OCI application containers, and virtual machines through a single control plane. It brings together cluster infrastructure management, secure multi-tenancy, software-defined networking, and pluggable storage backend orchestration into one cohesive system exposed via a full REST API and command-line interface. What distinguishes Incus is its ability to run multiple instance types side by side—full Linux system containers, OCI application containers, and QEMU virtual machines—all managed with consistent tooling. Networkin
Connects a managed network to a container or virtual machine as a NIC device with a chosen interface name.
Testcontainers for .NET es una biblioteca de pruebas de Docker y un framework de pruebas de integración diseñado para gestionar el ciclo de vida de contenedores desechables. Proporciona abstracciones de alto nivel como un wrapper de la API de Docker para aprovisionar infraestructura efímera, reemplazando mocks con instancias reales de bases de datos, mensajería y motores de búsqueda para garantizar entornos de prueba aislados y reproducibles. El proyecto se distingue por un patrón de configuración de contenedor mediante constructor y un mecanismo de enlace de puertos dinámico que evita colisiones durante la ejecución concurrente de pruebas. Permite una comunicación servicio a servicio confiable a través de orquestación de red virtual y alias de red, y garantiza la disponibilidad del servicio mediante comprobaciones de preparación basadas en polling para endpoints HTTP y puertos TCP. La biblioteca proporciona módulos especializados para bases de datos relacionales, NoSQL y vectoriales, así como brokers de mensajería y emuladores de servicios en la nube. Su superficie de capacidades se extiende a la configuración de imágenes de contenedor, recolección de logs y la simulación de condiciones de red para verificar la resiliencia del sistema. Admite la conectividad a runtimes de Docker locales y remotos a través de variables de entorno y archivos de configuración estandarizados.
Allows attaching existing containers to virtual networks to enable communication between disparate resources.
Pipework es un kit de herramientas de redes definidas por software y una utilidad de gestión diseñada para automatizar configuraciones de red para Linux Containers. Proporciona herramientas para gestionar direcciones IP, crear topologías de red virtuales e integrar contenedores en diversas arquitecturas de red. El proyecto se distingue por su soporte especializado para la configuración de dispositivos InfiniBand IPoIB, incluyendo la gestión de claves de partición. También cuenta con integración con Open vSwitch para la automatización de puentes y aislamiento VLAN, así como la capacidad de vincular contenedores directamente al hardware físico del host mediante subinterfaces macvlan. Sus capacidades más amplias cubren una gestión de red integral, incluyendo asignación de IP estática y DHCP, manipulación de reglas de enrutamiento y configuración de puerta de enlace predeterminada. También incluye utilidades para monitorear la disponibilidad de interfaces y simular condiciones de red como latencia y pérdida de paquetes dentro de los espacios de nombres de los contenedores.
Executes network configuration commands directly within isolated Linux network namespaces to ensure container traffic separation.
The project provides an open container runtime specification and standardized schema for defining container configurations, namespaces, resource limits, security policies, and filesystem mounts across platforms. It outlines the formal configuration formats, lifecycle operations, and execution environments necessary for portable, isolated container workloads. The specification covers container lifecycle management protocols and structured rules governing container creation, execution startup, process signaling, state tracking, and resource teardown. It standardizes local bundle packaging and
Transfers physical or virtual network devices into container network namespaces for connectivity.