awesome-repositories.com
ब्लॉग
MCP
awesome-repositories.com

AI-संचालित खोज के साथ बेहतरीन ओपन-सोर्स रिपॉजिटरी खोजें।

एक्सप्लोर करेंक्यूरेटेड खोजेंओपन-सोर्स विकल्पसेल्फ-होस्टेड सॉफ्टवेयरब्लॉगसाइटमैप
प्रोजेक्टMCP सर्वरहमारे बारे मेंहम रैंकिंग कैसे करते हैंप्रेस
कानूनीगोपनीयताशर्तें
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

12 रिपॉजिटरी

Awesome GitHub RepositoriesPID Namespace Isolation

Isolates the sandbox's process list so it cannot see or signal processes outside the sandbox.

Distinct from Namespace-Based Isolation: Distinct from Namespace-Based Isolation: focuses specifically on PID namespace isolation for process hiding, not general kernel namespace isolation.

Explore 12 awesome GitHub repositories matching operating systems & systems programming · PID Namespace Isolation. Refine with filters or upvote what's useful.

Awesome PID Namespace Isolation GitHub Repositories

AI के साथ बेहतरीन रिपॉजिटरी खोजें।हम AI का उपयोग करके सबसे सटीक रिपॉजिटरी खोजेंगे।
  • yeasy/docker_practiceyeasy का अवतार

    yeasy/docker_practice

    26,111GitHub पर देखें↗

    This project is a Docker educational resource and a collection of practical examples designed for learning containerization technologies. It serves as a guide for understanding container fundamentals, including the creation and management of custom images and the use of registries. The repository provides specialized references for container security hardening, such as managing kernel privileges and implementing supply chain security. It also includes tutorials for multi-container orchestration and a DevOps guide focused on CI/CD automation and image optimization. The material covers a broad

    Explains the use of kernel namespaces to separate system resources and prevent process interference.

    Gobookcloud-computingcontainer
    GitHub पर देखें↗26,111
  • socketio/socket.io-clientsocketio का अवतार

    socketio/socket.io-client

    10,601GitHub पर देखें↗

    Socket.IO Client is a real-time WebSocket client library that establishes persistent bidirectional connections to a server, with automatic fallback to HTTP long-polling when WebSocket connections are unavailable. It provides an event-based bidirectional messaging framework where clients and servers exchange named events with serializable data, supporting acknowledgements and timeouts for reliable communication. The client distinguishes itself through automatic reconnection with exponential backoff, maintaining connection reliability by monitoring health and reconnecting with increasing delays

    Partitions a single connection into isolated logical namespaces for separating application logic and authorization boundaries.

    browserjavascriptnodejs
    GitHub पर देखें↗10,601
  • containers/bubblewrapcontainers का अवतार

    containers/bubblewrap

    5,839GitHub पर देखें↗

    Bubblewrap is a Linux sandbox runner that creates lightweight, isolated execution environments for running untrusted applications. It combines Linux user, mount, network, PID, and UTS namespaces with seccomp-BPF system call filtering to restrict filesystem, network, process, and inter-process communication access. The project provides comprehensive process isolation by giving each sandbox its own private tmpfs root with selective bind-mounts, a separate network stack containing only a loopback interface, an independent process ID space, and remapped user and group identifiers. It applies secc

    Isolates the sandbox's process list so it cannot see or signal processes outside the sandbox.

    Clinux-containersuser-namespaces
    GitHub पर देखें↗5,839
  • cri-o/cri-ocri-o का अवतार

    cri-o/cri-o

    5,629GitHub पर देखें↗

    CRI-O is an open-source container runtime that implements the Kubernetes Container Runtime Interface (CRI) to manage container images, pods, and containers on cluster nodes using OCI-compatible runtimes. It serves as a node-level container manager that handles image pulling, container lifecycle, and resource monitoring for Kubernetes clusters, running containers according to the Open Container Initiative specifications. The runtime distinguishes itself through live configuration reloading that applies changes to runtime definitions, registry mirrors, and TLS certificates without restarting th

    Skips the infra container when pod-level PID namespace is not requested, as an experimental feature.

    Go
    GitHub पर देखें↗5,629
  • binpash/trybinpash का अवतार

    binpash/try

    5,435GitHub पर देखें↗

    Try एक ऐसा टूल है जो ephemeral शेल एनवायरनमेंट को मैनेज करने और एक आइसोलेटेड सैंडबॉक्स के भीतर कमांड चलाने के काम आता है। यह OverlayFS और Linux namespaces का उपयोग करता है ताकि प्रोसेस लाइव सिस्टम को बदल न सकें, और यह एक कमांड सैंडबॉक्स और फाइलसिस्टम चेंज ऑडिटर दोनों के रूप में कार्य करता है। यह प्रोजेक्ट उपयोगकर्ताओं को अस्थायी लेयर में फाइल में हुए बदलावों को कैप्चर करने और उन्हें लागू करने या हटाने का निर्णय लेने से पहले उनकी जांच करने की सुविधा देता है। यह बदलावों को ऑडिट करने और फिर सत्यापित बदलावों को होस्ट फाइलसिस्टम में मर्ज करने के वर्कफ़्लो का समर्थन करता है। यह टूल इंटरैक्टिव सैंडबॉक्स शेल, कस्टम सैंडबॉक्स डायरेक्टरी मैनेजमेंट और कई ओवरले डायरेक्टरी को एक लेयर्ड एनवायरनमेंट में मर्ज करने की क्षमता प्रदान करता है। इसमें कमांड और फ्लैग के ऑटो-कंप्लीशन के लिए शेल कंप्लीशन स्क्रिप्ट भी शामिल हैं।

    Provides a sandbox that uses Linux namespaces and OverlayFS to execute commands without altering the host system.

    Shelladministrationcontainersshell
    GitHub पर देखें↗5,435
  • cilium/tetragoncilium का अवतार

    cilium/tetragon

    4,753GitHub पर देखें↗

    Tetragon Linux और Kubernetes वातावरण के लिए डिज़ाइन किया गया एक eBPF-आधारित रनटाइम सिक्योरिटी और ऑब्जर्वेबिलिटी टूलसेट है। यह एक सिक्योरिटी पॉलिसी मैनेजर, ऑब्जर्वेबिलिटी एजेंट और एनफोर्समेंट इंजन के रूप में कार्य करता है जो प्रिविलेज एस्केलेशन, कंटेनर एस्केप और अनधिकृत सिस्टम गतिविधि का पता लगाने के लिए कर्नल फंक्शन्स और ट्रेसपॉइंट्स को हुक करता है। यह प्रोजेक्ट रियल-टाइम, इन-कर्नल एनफोर्समेंट करने की अपनी क्षमता के माध्यम से अलग है, जो इसे सिस्टम कॉल पूरा होने से पहले दुर्भावनापूर्ण प्रोसेस को सिंक्रोनस रूप से समाप्त करने या फंक्शन रिटर्न वैल्यू को संशोधित करने की अनुमति देता है। यह कंटेनर आइडेंटिटी को सिंक्रोनाइज़ करके और लो-लेवल कर्नल इवेंट्स को सीधे पॉड्स और नेमस्पेस से मैप करके गहरा Kubernetes इंटीग्रेशन प्रदान करता है। इसकी व्यापक क्षमताओं में सिस्टम कॉल ऑडिटिंग, नेटवर्क कनेक्शन ट्रैकिंग और फाइल इंटीग्रिटी मॉनिटरिंग शामिल है। यह सिस्टम डायनामिक पॉलिसी मैनेजमेंट का समर्थन करता है और BPF परफॉरमेंस और रिसोर्स यूटिलाइजेशन की निगरानी के लिए डायग्नोस्टिक टूल्स प्रदान करता है। डिप्लॉयमेंट का समर्थन Helm चार्ट्स के माध्यम से Kubernetes क्लस्टर्स में, साथ ही स्टैंडअलोन कंटेनर्स और नेटिव ऑपरेटिंग सिस्टम पैकेजों के माध्यम से किया जाता है।

    Tracks Linux namespace operations to detect when processes attempt to switch namespaces.

    C
    GitHub पर देखें↗4,753
  • aliyuncontainerservice/pouchAliyunContainerService का अवतार

    AliyunContainerService/pouch

    4,648GitHub पर देखें↗

    Pouch is a Linux container runtime and OCI container engine designed to execute containerized applications. It functions as a Kubernetes container runtime, integrating with orchestrators to manage the lifecycle of pods and isolated application environments. The project features a peer-to-peer image distribution system to deliver large container images across large-scale clusters while reducing bandwidth load. It also provides support for legacy Linux kernel versions, allowing modern container runtimes to maintain compatibility with older hardware. The runtime implements application isolation

    Uses Linux namespaces and control groups to create isolated environments that prevent process interference.

    Go
    GitHub पर देखें↗4,648
  • hackerschoice/thc-tips-tricks-hacks-cheat-sheethackerschoice का अवतार

    hackerschoice/thc-tips-tricks-hacks-cheat-sheet

    3,853GitHub पर देखें↗

    This project is a comprehensive command-line reference and toolkit designed for Linux system administration and network security assessment. It provides a collection of technical snippets and operational guides focused on managing remote environments, orchestrating shell sessions, and executing administrative tasks through native terminal utilities. The repository distinguishes itself by offering specialized techniques for stealthy operations and infrastructure manipulation. It covers methods for establishing encrypted tunnels to bypass firewalls, obfuscating process identities and command hi

    Modifies execution environments using kernel namespaces to hide processes or isolate applications.

    Shell
    GitHub पर देखें↗3,853
  • opencontainers/runtime-specopencontainers का अवतार

    opencontainers/runtime-spec

    3,641GitHub पर देखें↗

    The project provides an open container runtime specification and standardized schema for defining container configurations, namespaces, resource limits, security policies, and filesystem mounts across platforms. It outlines the formal configuration formats, lifecycle operations, and execution environments necessary for portable, isolated container workloads. The specification covers container lifecycle management protocols and structured rules governing container creation, execution startup, process signaling, state tracking, and resource teardown. It standardizes local bundle packaging and

    Applies operating system namespaces to isolate process visibility and network connectivity.

    Gocontainersdockeroci
    GitHub पर देखें↗3,641
  • checkpoint-restore/criucheckpoint-restore का अवतार

    checkpoint-restore/criu

    3,697GitHub पर देखें↗

    CRIU is a Linux process checkpointing tool and state manager used to freeze running applications and save their memory and state to disk for later restoration. It functions as a container migration engine and an OCI checkpoint image converter, allowing the live state of running containers to be transferred between different hosts. The project distinguishes itself through its ability to persist network connectivity, acting as a TCP connection state persister that saves and reconstructs network socket states to maintain active communication after a restart. It further enables the distribution o

    Creates a new PID namespace during restoration to prevent process ID conflicts when restarting applications.

    Cblcrcheckpointcontainer
    GitHub पर देखें↗3,697
  • zebbern/claude-code-guidezebbern का अवतार

    zebbern/claude-code-guide

    3,441GitHub पर देखें↗

    This project provides a framework for AI agent orchestration and context management, enabling the deployment of specialized AI personas and subagents to solve multi-step technical goals. It centers on managing specialized agents with isolated contexts and role-based prompts to handle domain-specific tasks. The system differentiates itself through a hierarchical project memory using markdown files to maintain coding standards and a secure execution model that utilizes sandboxed environments and git worktree isolation. It also features a Model Context Protocol integration for external tool conn

    Runs commands in a sandbox with namespace isolation and network restrictions to prevent unauthorized system access.

    aiai-agentai-agent-tools
    GitHub पर देखें↗3,441
  • rootless-containers/rootlesskitrootless-containers का अवतार

    rootless-containers/rootlesskit

    1,273GitHub पर देखें↗

    RootlessKit is a tool for running container workloads and isolated process trees securely as a standard non-privileged user without holding root access on the host. It creates unprivileged user and mount namespaces to simulate fake root execution environments, allowing users to execute container workloads and manage resource groups safely. The project provides capabilities for rootless port forwarding and unprivileged network namespace isolation, routing container network traffic through user-mode packet translation without requiring privileged kernel setup. It includes multiple backend netwo

    Executes child processes inside dedicated namespaces to contain process trees and terminate internal tasks upon exit.

    Gorootless-containers
    GitHub पर देखें↗1,273
  1. Home
  2. Operating Systems & Systems Programming
  3. Kernel and Core Internals
  4. Process and Memory Management
  5. Process Isolation
  6. Namespace-Based Isolation
  7. PID Namespace Isolation

सब-टैग एक्सप्लोर करें

  • Infra Container SkippersSkips the infra container when a pod-level PID namespace is not requested, as an experimental feature. **Distinct from PID Namespace Isolation:** Distinct from PID Namespace Isolation: focuses on skipping the infra container based on PID namespace request, not on isolating process lists.
  • Process Namespace Isolation2 सब-टैग्सTechniques for isolating subprocesses using kernel namespaces to restrict system and network access. **Distinct from PID Namespace Isolation:** Generalizes the specific PID/IPC isolation candidates to overall sandbox namespace and network restriction.