For container runtime specifications, the strongest matches are aliyuncontainerservice/pouch (Pouch is a container runtime and execution engine implementing), containers/crun (crun is a low-level container runtime implemented in C) and youki-dev/youki (Youki is a Rust-based low-level container runtime that directly). containerd/containerd and opencontainers/runtime-spec round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.
Hand-picked container runtime specifications for developers. Compare the top OCI-compliant standards and find the right one for your project.
Pouch is a Linux container runtime and OCI container engine designed to execute containerized applications. It functions as a Kubernetes container runtime, integrating with orchestrators to manage the lifecycle of pods and isolated application environments. The project features a peer-to-peer image distribution system to deliver large container images across large-scale clusters while reducing bandwidth load. It also provides support for legacy Linux kernel versions, allowing modern container runtimes to maintain compatibility with older hardware. The runtime implements application isolation
Pouch is a container runtime and execution engine implementing OCI standards and isolation features, making it a fitting tool for this search though it also includes higher-level orchestration and distribution features.
crun is a low-level container runtime that implements the Open Container Initiative specification for managing the lifecycle of isolated processes. It provides the core mechanisms for container creation, execution, and deletion, ensuring compatibility across platforms through standardized lifecycle management. The project distinguishes itself by offering a shared C library that allows container runtime operations to be embedded directly into other compiled applications. It further extends execution capabilities through specialized handlers that enable the deployment of containers within isola
crun is a low-level container runtime implemented in C that directly fulfills the Open Container Initiative specification for process isolation and container lifecycle management.
Youki is a low-level container runtime written in Rust that creates and manages isolated containers according to Open Container Initiative specifications. It serves as an execution engine that can function as a rootless container manager or a pluggable Kubernetes CRI runtime to manage pods and containers within a cluster. The project distinguishes itself by providing a Wasm container runtime capable of executing WebAssembly modules as isolated workloads compatible with standard orchestration tools. It further supports a rootless execution model, allowing isolated environments to start as non-
Youki is a Rust-based low-level container runtime that directly implements OCI specifications, providing namespace and sandbox isolation, rootless execution, seccomp support, and Wasm container capabilities.
Containerd is a daemon-based container runtime that manages the complete lifecycle of containers on a host system. It functions as a core orchestration backend, handling image distribution, storage, and process execution while adhering to industry-standard specifications for container execution and configuration. The project is distinguished by its modular, plugin-based architecture, which allows for the extension of storage, runtime, and networking capabilities without requiring a full daemon recompile. It utilizes a shim-based execution model to delegate low-level operations, ensuring isola
Containerd is an industry-standard, OCI-compliant container runtime that manages low-level process execution, storage, and lifecycle handling on a host system.
The project provides an open container runtime specification and standardized schema for defining container configurations, namespaces, resource limits, security policies, and filesystem mounts across platforms. It outlines the formal configuration formats, lifecycle operations, and execution environments necessary for portable, isolated container workloads. The specification covers container lifecycle management protocols and structured rules governing container creation, execution startup, process signaling, state tracking, and resource teardown. It standardizes local bundle packaging and
This is the official Open Container Initiative runtime specification repository, providing the exact standard and low-level execution definitions you are looking for.
This project is an OCI-compatible container runtime that executes workloads within lightweight virtual machines. By leveraging hardware-based virtualization, it provides strong security isolation between containerized processes and the host operating system, serving as a drop-in replacement for traditional container execution environments. The runtime distinguishes itself through a hypervisor-agnostic architecture that abstracts underlying virtualization operations, allowing for consistent container lifecycle management across different backends. It integrates directly with standard container
This repository provides an OCI-compatible container runtime that executes workloads inside lightweight virtual machines, delivering strong hardware-based sandbox isolation and standardized container execution.
Youki is an OCI container runtime written in Rust. It implements the Open Container Initiative runtime specification to manage the lifecycle of containerized processes and ensure compatibility with standard container images and engines. The runtime is designed for memory safety and supports rootless container execution, allowing containers to run as non-root users to reduce security risks and limit privilege escalation. It provides core container management capabilities, including spawning and managing OCI containers. This is achieved through Linux namespace isolation, cgroup-based resource
Youki is an OCI-compliant low-level container runtime written in Rust that implements the Open Container Initiative specification, though it lacks explicit mention of seccomp and AppArmor features in the provided description.
Docker CE is an OCI compliant container platform and runtime engine used for building and running applications within isolated environments. It functions as a Linux container orchestrator and provides a command-line interface to manage the entire lifecycle of running application instances. The platform enables containerized application deployment and cross-platform software distribution by packaging software with its dependencies. It supports microservices architecture management and the creation of reproducible local development environments. The system includes capabilities for application
Docker CE provides OCI-compliant container execution and lifecycle management, though it functions as a comprehensive platform and orchestrator rather than a standalone low-level runtime specification or engine.
This project is a secure container runtime that provides strong isolation for application workloads by implementing a userspace kernel. By intercepting system calls and executing them within a memory-safe, restricted environment, it minimizes the attack surface exposed to the host kernel. It functions as a drop-in engine for standard container orchestration platforms, ensuring compatibility with industry-standard runtime specifications while maintaining a hardened execution boundary. The runtime distinguishes itself through its ability to virtualize core system resources, including an indepen
This project is a secure container runtime implementing a userspace kernel to provide strong sandbox isolation and OCI compatibility, making it a relevant low-level execution environment for this search.
CRI-O is an open-source container runtime that implements the Kubernetes Container Runtime Interface (CRI) to manage container images, pods, and containers on cluster nodes using OCI-compatible runtimes. It serves as a node-level container manager that handles image pulling, container lifecycle, and resource monitoring for Kubernetes clusters, running containers according to the Open Container Initiative specifications. The runtime distinguishes itself through live configuration reloading that applies changes to runtime definitions, registry mirrors, and TLS certificates without restarting th
CRI-O is a Kubernetes-focused container runtime implementing the CRI standard using OCI-compliant execution environments, fulfilling the low-level execution and standard interface requirements well.
Moby is an OCI container engine and runtime manager designed for building, running, and managing isolated containers based on Open Container Initiative standards. It functions as a container daemon and image builder, providing a core engine to orchestrate the full lifecycle of containers and the packaging of source code into portable images. The project provides a standardized HTTP interface that allows for programmatic container management, enabling external clients to control daemon settings and container operations. It supports a rootless security model, allowing the engine daemon to execu
Moby is a comprehensive container engine and runtime manager that implements OCI standards for building and running isolated environments, though it focuses more on orchestration and daemon management than being a bare-bones low-level specification runner.
rkt is a pod-native container engine and runtime for Linux that executes containerized applications as isolated pods. It serves as an OCI container runtime and a Linux container manager, supporting the execution of images based on Open Container Initiative, appc, and Docker specifications. The project distinguishes itself by offering hardware-level container isolation, allowing pods to run within virtual machines using KVM or QEMU for a dedicated kernel. It further separates itself through secure container deployment practices, utilizing SELinux mandatory access control and TPM-backed integri
rkt is a pod-native container engine and runtime that implements OCI specifications and low-level container execution, making it a relevant tool for isolated container environments despite being deprecated.
Kata Containers is an OCI container runtime that launches containers inside lightweight virtual machines to combine hardware-level isolation with container operational speed. It functions as a hardware-isolated container engine and lightweight VM hypervisor, providing a virtual machine monitor interface that abstracts multiple hypervisors to optimize for performance or specific hardware emulation. The project distinguishes itself through a confidential computing runtime that leverages hardware-backed trusted execution environments, such as Intel TDX and AMD SEV-SNP, to protect data in use. It
Kata Containers is an OCI-compliant low-level container runtime that uses lightweight virtual machines for hardware-level isolation, matching the core execution and standardization requirements.
runV is a hypervisor-based runtime for OCI.
RunV is a hypervisor-based OCI-compliant container runtime that provides strong isolation, fitting the need for low-level execution environments and standardized container interfaces.
| रिपॉजिटरी | स्टार्स | भाषा | लाइसेंस | अंतिम पुश |
|---|---|---|---|---|
| aliyuncontainerservice/pouch | 4.6K | Go | Apache-2.0 | |
| containers/crun | 4K | C | GPL-2.0 | |
| youki-dev/youki | 7.5K | Rust | Apache-2.0 | |
| containerd/containerd | 20.4K | Go | apache-2.0 | |
| opencontainers/runtime-spec | 3.6K | Go | Apache-2.0 | |
| kata-containers/runtime | 2.1K | Go | Apache-2.0 | |
| containers/youki | 7.5K | Rust | Apache-2.0 | |
| docker/docker-ce | 5.8K | Go | Apache-2.0 | |
| google/gvisor | 17.7K | Go | apache-2.0 | |
| cri-o/cri-o | 5.6K | Go | Apache-2.0 |