A lightweight process isolation tool that utilizes Linux namespaces, cgroups, rlimits and seccomp-bpf syscall filters, leveraging the Kafel BPF language for enhanced security.
-
Updated
Apr 13, 2026 - C++
A lightweight process isolation tool that utilizes Linux namespaces, cgroups, rlimits and seccomp-bpf syscall filters, leveraging the Kafel BPF language for enhanced security.
Lightweight, cross-platform process sandboxing powered by OpenAI Codex's runtime. Sandbox any command with file, network, and credential controls.
Sample application that shows how to create a Plugin Framework for a WPF application
A .NET tool that uses AppDomain's to enable dynamic execution and escape detection.
Joblet is a micro-container runtime for running Linux jobs with: Process and filesystem isolation (PID namespace, chroot) Fine-grained CPU, memory, and IO throttling (cgroups v2) Secure job execution with mTLS and RBAC Built-in scheduler, SSE log streaming, and multi-core pinning Ideal for: Agentic AI Workloads (Untrusted code)
A lightweight process isolation tool, requiring absolutely no privileges to run
AI Agent Runtime Engine: Long-lived sessions for Claude Code & OpenCode
A high-performance serverless runtime for Node.js functions in Go. Packages and executes functions in pooled, isolated containers with fast invocation speeds and a streamlined deploy and invoke workflow.
A library for .NET framework applications to discover, install, and manage plugins from NuGet feeds, running each plugin in an isolated process for maximum stability.
It's a fancy process isolation tool that creates an isolated environment for your binary in under 10 minutes and lets you reset the execution state in under seconds. All this, with a couple of one-liner commands from your trusty terminal.
Run marked pytest tests in grouped subprocesses (cross-platform).
Isolated OTP application management system for Elixir/Erlang
Sandbox untrusted Rust code with isolated processes
Isolation sandbox for AI agents — process, namespace, and Firecracker capsules
The GenCyber 10 Security First Principles are a set of fundamental best practices and guidelines for cybersecurity
A light process isolation sandbox used for Competitive Programming contest
Modern C++23 sandboxing and process isolation library. Provides a clean API for launching processes with resource limits, timeouts, and controlled execution. Currently Windows-only (Job Objects), with Linux/macOS planned.
A Toy linux Container With Alpine Linux Mini Root File System
secure cage made of namespaces
Add a description, image, and links to the process-isolation topic page so that developers can more easily learn about it.
To associate your repository with the process-isolation topic, visit your repo's landing page and select "manage topics."