{"repo":"nestybox/sysbox","free":true,"listed":false,"github":"https://github.com/nestybox/sysbox","clone":"git clone https://github.com/nestybox/sysbox.git","description":"An open-source, next-generation \"runc\" that empowers rootless containers to run workloads such as Systemd, Docker, Kubernetes, just like VMs.","language":"Shell","stars":3828,"topics":["containers","container-runtimes","container-runtime-security","docker","kubernetes","devops"],"license":"Apache-2.0","category":"deployment-docker-iac","readme_excerpt":"Introduction Sysbox is an open-source and free container runtime (a specialized \"runc\"), originally developed by Nestybox ([acquired by Docker][docker-acquisition] on 05/2022), that enhances containers in two key ways: Improves container isolation: Linux user-namespace on all containers (i.e., root user in the container has zero privileges on the host). Virtualizes portions of procfs & sysfs inside the container. Hides host info inside the container. Locks the container's initial mounts, and more. Enables containers to run same workloads as VMs : With Sysbox, containers can run system-level software such as systemd, Docker, Kubernetes, K3s, buildx (including multi-arch builds), legacy apps, multi-arch apps, and more seamlessly & securely. This software can run inside Sysbox containers without modification and without using special versions of the software (e.g., rootless variants). No privileged containers, no complex images, no tricky entrypoints, no special volume mounts, etc. Think of it as a \"container supercharger\" : it enables your existing container managers / orchestrators (e.g., Docker, Kubernetes, etc.) to deploy containers that have hardened isolation and can run almost any workload that runs in VMs. Sysbox does this by making the container resemble a VM-like environment as much as possible, using advanced OS virtualization techniques. Unlike alternative runtimes such as Kata and KubeVirt, it does not use VMs . This makes it easier to use (particularly in cloud env","default_branch":null,"files":null,"tree":[],"storefront":"/r/nestybox","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/nestybox/sysbox/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}