awesome-repositories.com
Blog
awesome-repositories.com

Descoperă cele mai bune repository-uri open source cu căutare AI.

ExploreazăCăutări recomandateAlternative open-sourceSoftware self-hostedBlogHartă site
ProiectDespreCum realizăm clasamentulPresăServer MCP
LegalConfidențialitateTermeni
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
mviereck avatar

mviereck/x11docker

0
View on GitHub↗
6,283 stele·417 fork-uri·Shell·MIT·4 vizualizări

X11docker

x11docker este un orchestrator de containere OCI cu interfață grafică și o punte hardware concepută pentru a rula aplicații grafice și medii desktop complete în interiorul containerelor. Acesta funcționează ca un sandbox Linux GUI, conectând procesele containerizate la serverele de afișare X11 sau Wayland și la sistemele audio ale gazdei.

Proiectul se diferențiază prin integrarea profundă a sistemului pentru accelerare hardware, inclusiv automatizarea driverelor NVIDIA și GPU passthrough. Suportă emularea GUI cross-architecture și oferă capabilități de acces la distanță prin VNC, SSH forwarding și randare HTML5 în browser.

Instrumentul acoperă o gamă largă de capabilități de integrare, inclusiv maparea identității prin user-namespace pentru securitate, bridging pentru sesiuni D-Bus pentru comunicarea între procese și sincronizarea bidirecțională a clipboard-ului. De asemenea, gestionează partajarea perifericelor precum camere web și imprimante, precum și gestionarea sistemelor init și montarea stocării persistente.

Software-ul este implementat ca un utilitar bazat pe shell care suportă mai multe backend-uri compatibile OCI, inclusiv Docker și Podman.

Features

  • OCI GUI Orchestrators - Acts as an orchestrator to execute graphical applications and desktop environments inside Docker or Podman.
  • Containerized Desktop Sessions - Launches full desktop environments with window managers and GPU acceleration inside isolated containers.
  • Audio Socket Routing - Shares PulseAudio or PipeWire sockets to connect containerized audio streams to the host sound server.
  • Container User Identity Mapping - Maps container user and group IDs to those of the host to ensure correct file permissions and security.
  • GUI-Aware Process Management - Connects containerized processes to host X11/Wayland display servers and audio systems.
  • GPU Hardware Acceleration - Enables high-performance rendering and compute by interfacing containers with host GPUs.
  • X11 Display Forwarders - Maps host X11 or Wayland sockets into the container to render graphical interfaces on the host screen.
  • Audio Server Integration - Shares PulseAudio or ALSA sockets with the container to enable sound playback and recording.
  • Containerized Launchers - Starts full desktop environments with window managers and GPU acceleration inside a container.
  • Socket Sharing - Shares the host Wayland socket to execute native Wayland applications inside containers.
  • Hardware Bridges - Provides the core bridging mechanism that allows containerized applications to access host GPUs, clipboards, and hardware peripherals.
  • Hardware Device Sharing - Grants containers shared access to physical host peripherals like webcams and printers.
  • Linux Sandboxes - Functions as a security-focused sandbox for running untrusted graphical software in isolated containers.
  • Physical Device Pass-through - Maps host hardware device nodes and drivers into containers for direct peripheral and GPU access.
  • Hardware Passthrough - Maps physical host hardware devices like webcams and printers directly into containerized environments.
  • X11 Display Server Management - Manages X servers and Wayland compositors to coordinate graphical output for containerized apps.
  • Privilege Dropping - Creates a non-root user matching the host user and drops unnecessary kernel capabilities to minimize the attack surface.
  • X Server Access Controls - Configures X authority cookies and xhost policies to secure the graphical connection between the host and the container.
  • GUI Application Bridges - Provides a bridge to launch and display graphical applications from containers on the host desktop.
  • Persistent Storage Volumes - Maps host directories or volumes to the container to preserve user data across sessions.
  • Clipboard Synchronization - Synchronizes text and data between the host and container using unidirectional or bidirectional transfer modes.
  • Container-to-Host Application Export - Creates native desktop shortcuts for containerized graphical apps to enable quick execution from the host.
  • Session Detachment and Reattachment - Integrates with xpra to allow detaching from and reattaching to remote GUI sessions without closing applications.
  • Multi-Architecture Container Runtimes - Runs container images built for different CPU architectures using emulation for cross-hardware compatibility.
  • User Session Daemons - Starts a DBus user session daemon to support application communication regardless of the chosen init system.
  • OCI Runtime Switching - Supports the use of different OCI-compliant runtimes such as Docker, Podman, or direct host execution.
  • Runtime Abstraction Layers - Provides a common interface to execute containers across different backends like Docker and Podman.
  • Remote GUI Access - Provides remote access to containerized desktops via VNC, SSH forwarding, and HTML5 rendering.
  • DBus Session Bridging - Enables inter-process communication by bridging the container to the host DBus system or starting a private session.
  • Nested X Servers - Starts nested servers and virtual frames to display containerized applications on the host.
  • Cross-Architecture Virtualization - Supports running container images built for different CPU architectures via emulation.
  • NVIDIA GPU Passthroughs - Automates the mapping of NVIDIA GPUs and driver versions from the host into containers.
  • X11 Authorization Tokens - Passes security tokens between the host and container to authorize X11 server connections.
  • X Client Namespace Isolation - Creates dedicated, isolated X server namespaces to prevent security leaks from containerized applications.
  • SSH Server Hosting - Runs an SSH daemon inside the container to enable remote shell access and graphical application execution.
  • X11 Display Security - Implements security mechanisms to isolate X11 display servers from untrusted containerized applications.
  • User Namespace Mappings - Synchronizes container user and group IDs with the host to ensure correct file permissions.
  • D-Bus Desktop Services - Provides bridging to the host system bus or initiates a private session for containerized desktop applications.
  • Container Init Process - Launches a service manager as PID 1 to handle system daemons and prevent zombie processes.
  • Browser-Based Remote Desktop Clients - Renders desktop applications as HTML5 web pages via Xpra or GTK3 Broadway for browser-based remote access.
  • VNC Server Hosting - Starts a VNC server within a container to provide remote graphical access to the containerized session.

Istoric stele

Graficul istoricului de stele pentru mviereck/x11dockerGraficul istoricului de stele pentru mviereck/x11docker

Căutare AI

Explorează mai multe repository-uri excelente

Descrie ce ai nevoie în limbaj simplu — AI-ul sortează mii de proiecte open source selectate în funcție de relevanță.

Start searching with AI

Alternative open-source pentru X11docker

Proiecte open-source similare, clasificate după numărul de funcționalități comune cu X11docker.
  • lxc/incusAvatar lxc

    lxc/incus

    4,893Vezi pe GitHub↗

    Incus is a unified orchestration platform for managing system containers, OCI application containers, and virtual machines through a single control plane. It brings together cluster infrastructure management, secure multi-tenancy, software-defined networking, and pluggable storage backend orchestration into one cohesive system exposed via a full REST API and command-line interface. What distinguishes Incus is its ability to run multiple instance types side by side—full Linux system containers, OCI application containers, and QEMU virtual machines—all managed with consistent tooling. Networkin

    Gocloudcontainershacktoberfest
    Vezi pe GitHub↗4,893
  • lxc/lxdAvatar lxc

    lxc/lxd

    5,554Vezi pe GitHub↗

    LXD is a unified platform for managing both system containers and virtual machines through a single REST API and command-line interface. It provides a programmatic HTTP interface for controlling the full lifecycle of instances, enabling automation and integration with external tools. The system runs unprivileged containers with per-instance UID/GID mappings, seccomp filters, and AppArmor profiles for kernel-level isolation, while supporting multiple storage backends including directory, Btrfs, LVM, ZFS, Ceph, LINSTOR, and TrueNAS through a unified driver interface. The platform distinguishes

    Go
    Vezi pe GitHub↗5,554
  • orbstack/orbstackAvatar orbstack

    orbstack/orbstack

    8,903Vezi pe GitHub↗

    OrbStack is a native macOS application that replaces Docker Desktop, providing an all-in-one environment for running Docker containers, full Linux virtual machines, and local Kubernetes clusters. It runs Linux VMs directly on the macOS hypervisor framework for near-native performance, uses VirtioFS for fast bidirectional file sharing between macOS and Linux, and leverages Rosetta for near-native x86 emulation on Apple Silicon. The system assigns predictable local domain names to containers and VMs with automatic HTTPS certificate generation, forwards ports via event-driven updates, and stores

    Shellcolimadockerdocker-desktop
    Vezi pe GitHub↗8,903
  • projectatomic/bubblewrapAvatar projectatomic

    projectatomic/bubblewrap

    7,731Vezi pe GitHub↗

    Bubblewrap is an unprivileged sandbox execution utility for Linux that isolates processes from the host system. It creates secure environments by leveraging Linux namespaces to separate system resources, including network, PID, and IPC stacks. The project distinguishes itself by enabling the execution of untrusted software without requiring root privileges on the host machine. It prevents privilege escalation by disabling the execution of setuid binaries and uses user identity mapping to isolate process permissions from the host operating system. The tool manages a comprehensive security sur

    C
    Vezi pe GitHub↗7,731
Vezi toate cele 30 alternative pentru X11docker→

Întrebări frecvente

Ce face mviereck/x11docker?

x11docker este un orchestrator de containere OCI cu interfață grafică și o punte hardware concepută pentru a rula aplicații grafice și medii desktop complete în interiorul containerelor. Acesta funcționează ca un sandbox Linux GUI, conectând procesele containerizate la serverele de afișare X11 sau Wayland și la sistemele audio ale gazdei.

Care sunt principalele funcționalități ale mviereck/x11docker?

Principalele funcționalități ale mviereck/x11docker sunt: OCI GUI Orchestrators, Containerized Desktop Sessions, Audio Socket Routing, Container User Identity Mapping, GUI-Aware Process Management, GPU Hardware Acceleration, X11 Display Forwarders, Audio Server Integration.

Care sunt câteva alternative open-source pentru mviereck/x11docker?

Alternativele open-source pentru mviereck/x11docker includ: lxc/incus — Incus is a unified orchestration platform for managing system containers, OCI application containers, and virtual… lxc/lxd — LXD is a unified platform for managing both system containers and virtual machines through a single REST API and… orbstack/orbstack — OrbStack is a native macOS application that replaces Docker Desktop, providing an all-in-one environment for running… projectatomic/bubblewrap — Bubblewrap is an unprivileged sandbox execution utility for Linux that isolates processes from the host system. It… machyve/xhyve — xhyve is a macOS virtual machine manager and virtualization tool that leverages the native hypervisor framework to run… x11libre/xserver — This project is an X11 window system server that coordinates graphical output and input devices. It functions as a…