Low-level unprivileged sandboxing tool used by Flatpak and similar projects
-
Updated
Sep 22, 2026 - C
Low-level unprivileged sandboxing tool used by Flatpak and similar projects
StemJail: Dynamic Role Compartmentalization
A pure-Go implementation of fakeroot using Linux user namespaces.
Simple desktop application sandboxing tool for GNU\Linux
Very experimental docker authorization plugin, disabling some trivial ways of gaining root via docker
Experiments with unshare
Limit SFTP access to a remote (Linux) system
Kernel patches for non-init user namespace on FUSE filesystem
Nesting containers with podman
Runs commands in Linux containers with configurable levels of isolation.
A nix shell running in a (thin) container
Droidspaces container kernel patches and flashable boot images for Xiaomi 17 (pudding, SM8850) on Android 17 / HyperOS 4.0.0.9-4.0.0.26 with the Android Common Kernel 6.12 GKI baseline
Low-level lightweight toolkit to build process-level isolation sandbox environment(s) in linux
Restricts unprivileged user namespaces to declared executables. A BPF LSM program on the kernel’s userns_create hook refuses a namespace to anything that has not been declared, so Flatpak and Bubblejail keep working on a system where namespaces are otherwise closed.
Static security auditing for Kubernetes Pod specs — Pod Security Standards, user namespaces, and SecurityContext, entirely offline. CLI + GitHub Action.
Minimalist LEGO-style bwrap profile management.
To associate your repository with the user-namespaces topic, visit your repo's landing page and select "manage topics."