Low-level unprivileged sandboxing tool used by Flatpak and similar projects
StemJail: Dynamic Role Compartmentalization
Simple desktop application sandboxing tool for GNU\Linux
A pure-Go implementation of fakeroot using Linux user namespaces.
Very experimental docker authorization plugin, disabling some trivial ways of gaining root via docker
Experiments with unshare
Kernel patches for non-init user namespace on FUSE filesystem
Runs commands in Linux containers with configurable levels of isolation.
Nesting containers with podman
A nix shell running in a (thin) container