sysbox
wsl-vpnkit
Our great sponsors
sysbox | wsl-vpnkit | |
---|---|---|
22 | 18 | |
2,517 | 2,070 | |
3.5% | - | |
8.6 | 2.5 | |
13 days ago | 5 months ago | |
Shell | Shell | |
Apache License 2.0 | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
sysbox
-
Podman Desktop: A Free OSS Alternative to Docker Desktop
You are probably referring to Sysbox (https://github.com/nestybox/sysbox), which I believe will meet your requirements (systemd, inner containers, security, etc).
Btw, Sysbox is already supported in Docker-Desktop (business tier only), so you can easily do what you want with this instruction:
$ docker run -it --rm -e SYSBOX_SYSCONT_MODE=TRUE nestybox/ubuntu-focal-systemd-docker:latest bash
Disclaimer: I'm Sysbox's co-creator and currently working for Docker.
- Sysbox: VM-Like Containers
- What companies are using golang and have source code in github?
-
SELinux is unmanageable; just turn it off if it gets in your way
One project in this space that looked quite promising to me is sysbox[0]. I've used them once for a gitlab runner set-up similar to what is described in their blog[1].
It's currently working great and I have not had any major crashes/incidents for at least the past 8 months.
[0]: https://github.com/nestybox/sysbox
[1]: https://blog.nestybox.com/2020/10/21/gitlab-dind.html
-
Jenkins in Docker: Running Docker in a Jenkins container
Today, things are very different. Docker-in-Docker has a more secure and safe approach with rootless containers and freemium tools like sysbox. Tools like sysbox let you run Docker-in-Docker without the -privileged flag and optimizes specific scenarios, like running multiple nodes of a Kubernetes cluster as ordinary containers.
-
Run untrusted code in sandbox
Right now I am going with sysbox rootless containers. https://github.com/nestybox/sysbox
-
Real-world stories of how we’ve compromised CI/CD pipelines
We’ve been using Sysbox (https://github.com/nestybox/sysbox) for our Buildkite based CI/CD setup, allows docker-in-docker without privileged containers. Paired with careful IAM/STS design we’ve ended up with isolated job containers with their own IAM roles limited to least-privilege.
-
Individual Docker Desktops vs hosting on a server?
A good alternative to the VM approach is to use Kubernetes + Sysbox (a next-gen "runc", free, open-source).
- Sysbox now works on K8s v1.21
-
Does running a container with privileged mode turn on allow code to escape into the Host ?
But nowadays there is an option to run such software in containers securely. It's called Sysbox, and it's a new "runc" (the piece of software that creates the containers). I am one of the developers, so I am biased, but I think you'll find it helpful.
wsl-vpnkit
-
Windows Subsystem for Linux gets new 'mirrored' network mode
Mirrored network mode sounds quite a lot like what wsl-vpnkit does: https://github.com/sakai135/wsl-vpnkit
This came from Docker Desktop for Windows, where they needed a solution for VPNs like GlobalProtect and AnyConnect that are often configured to drop packets for networks that aren't the main one associated with the VPN.
-
Windows Subsystem for Linux 2.0 release
I'm going to wait a while to see how the new VPN stuff works out. Previously WSL2 didn't work with a Windows VPN without an extra tool ( https://github.com/sakai135/wsl-vpnkit ), hopefully this might fix things, but not going to risk trying it in case it breaks everything.
-
Simple PowerShell things allowing you to dig a bit deeper than usual
https://github.com/sakai135/wsl-vpnkit fixes that problem for me, and is less annoying than other fixes I tried
-
Can't use Warp Zero Trust on WSL 2
So i installed warp on windows and try to run go mod init to access few packages from my org private repo, and it says the repo not found, So i search and found that WSL 2 need this for Zero Trust to run on WSL 2 : https://github.com/sakai135/wsl-vpnkit , I've download and started the service but it still can't access the repo, does anyone has this problem when developing go with zero trust ?
-
Search domains
There's also a reference to https://github.com/sakai135/wsl-vpnkit, which looks like a much more ambitious effort to deal with this.
-
Make WSA (Windows Subsystem for Android) Run on Windows 10
If it works at all like WSL, you might want to look at wsl-vpnkit.
https://github.com/sakai135/wsl-vpnkit
It's not a proxy, but would give some idea how to shim into the middle.
-
Duality of man
there's a fix for that! https://github.com/sakai135/wsl-vpnkit
-
Unable to connect the internet in corporate office network
Have you tried wsl-vpnkit?
- Wsl-vpnkit: Provides network connectivity to WSL 2 when blocked by VPN
- Who else is forced to use Windows and how do you work around it?
What are some alternatives?
kata-containers - Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel and perform like containers, but provide the workload isolation and security advantages of VMs. https://katacontainers.io/
genie - A quick way into a systemd "bottle" for WSL
containerd - An open and reliable container runtime
gvisor - Application Kernel for Containers
dind - Docker in Docker
UTM - Virtual machines for iOS and macOS
runtime - Kata Containers version 1.x runtime (for version 2.x see https://github.com/kata-containers/kata-containers).
gatekeeper - 🐊 Gatekeeper - Policy Controller for Kubernetes
garden - Automation for Kubernetes development and testing. Spin up production-like environments for development, testing, and CI on demand. Use the same configuration and workflows at every step of the process. Speed up your builds and test runs via shared result caching
snekbox - Easy, safe evaluation of arbitrary Python code
PostgresApp - The easiest way to get started with PostgreSQL on the Mac