A lightweight process isolation tool that utilizes Linux namespaces, cgroups, rlimits and seccomp-bpf syscall filters, leveraging the Kafel BPF language for enhanced security.
-
Updated
Nov 26, 2025 - C++
A lightweight process isolation tool that utilizes Linux namespaces, cgroups, rlimits and seccomp-bpf syscall filters, leveraging the Kafel BPF language for enhanced security.
A lightweight, flexible, and safer alternative to chroot and/or Docker.
Root user privileges emulation layer
Simple "chroot" solution to build secure access. `Cystem` is a secure, reusable way to create and manage persistent Debian chroot environments with SSH and web terminal access. It uses modern software design patterns to provide a robust, maintainable, and secure system.
Add a description, image, and links to the chroot topic page so that developers can more easily learn about it.
To associate your repository with the chroot topic, visit your repo's landing page and select "manage topics."