1 repository
Applies security profiles using kernel isolation modules to restrict container actions.
Distinct from Runtime Access Controls: Distinct from Runtime Access Controls: focuses on OS-level kernel isolation modules and profiles rather than script-to-runtime bridges.
Explore 1 awesome GitHub repository matching security & cryptography · Kernel Security Enforcement. Refine with filters or upvote what's useful.
The project provides an open container runtime specification and standardized schema for defining container configurations, namespaces, resource limits, security policies, and filesystem mounts across platforms. It outlines the formal configuration formats, lifecycle operations, and execution environments necessary for portable, isolated container workloads. The specification covers container lifecycle management protocols and structured rules governing container creation, execution startup, process signaling, state tracking, and resource teardown. It standardizes local bundle packaging and
Applies security profiles using kernel isolation modules to restrict container actions.