Sandboxing All the Things with Flatpak and BubbleBox

This page summarizes the projects mentioned and recommended in the original post on news.ycombinator.com

InfluxDB - Purpose built for real-time analytics at any scale.
InfluxDB Platform is powered by columnar analytics, optimized for cost-efficient storage, and built with open data standards.
www.influxdata.com
featured
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com
featured
  • apparmor.d

    Full set of AppArmor profiles (~ 1500 profiles)

    If anyone want to look further into sandboxing applications on Linux, you can also look at AppArmor and the sandboxing features built into systemd.

    I love this repository for bases for AppArmor profiles[1], really good work. Never found a repository as good for systemd, but there are a few around.

    [1] https://github.com/roddhjav/apparmor.d

  • InfluxDB

    Purpose built for real-time analytics at any scale. InfluxDB Platform is powered by columnar analytics, optimized for cost-efficient storage, and built with open data standards.

    InfluxDB logo
  • pledge

    OpenBSD APIs ported to Linux userspace using SECCOMP BPF and Landlock LSM (by jart)

    Someone has combined those things to port Pledge to Linux.

    https://github.com/jart/pledge

  • firejail

    Linux namespaces and seccomp-bpf sandbox

    bubblewrap is designed as a low-level too. There is nothing quick and dirty about it. It disallows everything by default and you have to be explicit about what you want to share with the host. If your application needs complex permissions/resources, then you will need to have a complex bubblewrap command line.

    Once you have figured out which permissions/resources you need for a given program, you can wrap the command line invocation in a shell script.

    If you want other people to do the work of defining permissions/resources, then have a look at firejail: https://github.com/netblue30/firejail

  • flatpak-kcm

    Flatpak Permissions Management KCM

    If you're using KDE, they have a native permission manager: https://github.com/KDE/flatpak-kcm

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts

  • Anyone writes AppArmor profiles?

    1 project | /r/selfhosted | 20 Jun 2023
  • AppArmor and Profile Inheritance

    3 projects | /r/linuxquestions | 29 May 2023
  • How would you sandbox shady PDF files from the internet?

    1 project | /r/linuxquestions | 9 May 2023
  • Cybersec student here. How it possible that Linux is more secure than Windows?

    1 project | /r/linuxquestions | 16 Apr 2023
  • MacOS-like support for directory access control on Linux, *per app*

    1 project | /r/linuxquestions | 7 Apr 2023

Did you konow that C is
the 7th most popular programming language
based on number of metions?