7 dépôts
Mechanisms to secure access to container runtime APIs and sockets against unauthorized interaction.
Explore 7 awesome GitHub repositories matching security & cryptography · Container Daemon Security. Refine with filters or upvote what's useful.
Moby is an OCI container engine and runtime manager designed for building, running, and managing isolated containers based on Open Container Initiative standards. It functions as a container daemon and image builder, providing a core engine to orchestrate the full lifecycle of containers and the packaging of source code into portable images. The project provides a standardized HTTP interface that allows for programmatic container management, enabling external clients to control daemon settings and container operations. It supports a rootless security model, allowing the engine daemon to execu
Enables the container engine daemon to execute without root privileges to reduce the host security attack surface.
Traefik is a cloud-native edge router and API gateway designed to manage service communication and traffic flow across distributed infrastructure. It functions as a dynamic service proxy that automatically discovers backend services and configures routing rules in real time, eliminating the need for manual restarts or complex configuration updates. By integrating directly with container orchestrators and service registries, it maintains a consistent state for network traffic, load balancing, and security policy enforcement. The project distinguishes itself through its deep integration with di
Limits the host attack surface by proxying and filtering access to container runtime sockets.
This project is a Docker educational resource and a collection of practical examples designed for learning containerization technologies. It serves as a guide for understanding container fundamentals, including the creation and management of custom images and the use of registries. The repository provides specialized references for container security hardening, such as managing kernel privileges and implementing supply chain security. It also includes tutorials for multi-container orchestration and a DevOps guide focused on CI/CD automation and image optimization. The material covers a broad
Configures access rules for the container runtime API and sockets to prevent unauthorized remote host control.
Buildkit is a programmable container build toolkit and OCI container image builder that converts build definitions into concurrent dependency graphs for image construction. It functions as an OCI image distribution engine, capable of generating container images and exporting artifacts to local storage or remote registries. The project is distinguished by its use of a low-level binary intermediate representation to decouple high-level build languages from the execution engine. It supports multi-platform image builds through user-mode architecture emulation and provides a distributed build cach
Provides the ability to run the build daemon without administrative or root privileges to enhance security.
Buildah is a tool for creating OCI-compliant container images without requiring a background daemon process. It functions as a daemonless image constructor and distribution tool, allowing users to build, push, and pull images between local storage and remote registries. The project distinguishes itself by supporting unprivileged image building through the use of user namespaces and rootless mode. It enables direct modification of container root filesystems by mounting them to the host, allowing images to be treated as directories that can be manipulated via standard shell commands or scripts.
Enables image creation without root privileges by utilizing user namespaces and rootless mode.
Calico is a cloud-native networking and security solution designed to connect containerized workloads across virtual machines, bare metal, and multi-cloud environments. It provides a routing solution based on the Border Gateway Protocol to manage cluster traffic and implement the Container Network Interface for pod connectivity and IP address management. The project distinguishes itself through a security layer that enforces network policies based on identities and labels rather than static addresses. It includes a policy engine for controlling traffic flow, a cluster network encryptor for se
Creates a Unix Domain Socket between a pod and a host daemon to verify identity and enable secure communication.
Finch est un runtime de conteneurs basé sur une machine virtuelle et une CLI de gestion de conteneurs OCI utilisée pour le développement local. Il fonctionne en exécutant les charges de travail de conteneurs dans une machine virtuelle en arrière-plan pour les isoler du système d'exploitation hôte. Le projet sert de constructeur d'images OCI et d'orchestrateur de services multi-conteneurs pour simuler des environnements de production complexes sur une station de travail. Le runtime fonctionne comme un moteur de conteneurs multiplateforme, utilisant des couches d'émulation pour exécuter des images de conteneurs conçues pour des architectures CPU étrangères. Il se distingue dans la distribution d'images par la prise en charge du chargement différé (lazy-loading) et la génération d'index consultables, permettant aux conteneurs de démarrer avant qu'un téléchargement complet de l'image ne soit terminé. Le projet couvre un large éventail de capacités, notamment la gestion du cycle de vie des images OCI, la configuration des ressources de la machine virtuelle et l'orchestration d'applications multi-conteneurs. Il fournit des outils pour la gestion réseau, la persistance des volumes, ainsi que la signature et la vérification des images. Le système inclut une interface en ligne de commande avec prise en charge de l'autocomplétion du shell et compatibilité avec les commandes de conteneurs héritées.
Configures socket access and group permissions to operate the container engine without administrative or root privileges.