Effortlessly compose, extend, and observe every service in real-time for the first time ever.
oci-spec
Counted from the Cargo.toml manifests of the 29 indexed repositories that declare oci-spec as a dependency — not download counts. Dependency data last verified 2026-08-04.
Crates that show up unusually often in oci-spec projects. The most distinctive pairings rank first — crates these projects use far more than the average indexed Rust project does, not just crates that are popular everywhere. Each percentage is the share of oci-spec projects that also use it.
Instant, Concurrent, Secure & Lightweight Sandbox for AI Agents.
Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel and perform like containers, but provide the workload isolation and security advantages of VMs. https://katacontainers.io/
A container runtime written in Rust
🧱 local-first and microVM-backed programmable sandboxes for AI agents
Run any process, on your machine or in an AI agent's environment, as if it were a pod in your Kubernetes cluster: real env vars, DNS, network, traffic.
Hyperlight is a lightweight Virtual Machine Manager (VMM) designed to be embedded within applications. It enables safe execution of untrusted code within micro virtual machines with very low latency and minimal overhead.
A security-focused library OS supporting kernel- and user-mode execution
Compute substrate for AI agents: lightweight enough to live on your laptop, elastic enough to scale into the cloud and unleash unlimited resources.
Boot and upgrade via container images
A multi-sandbox container runtime that provides cloud-native, all-scenario multiple sandbox container solutions.
Facilitates running Wasm / WASI workloads managed by containerd
🐰 Bencher - Continuous Benchmarking
The lightest AI sandbox. A process-based sandbox for Linux, no container, no VM, no root, no prompt injection
Lightweight Sandbox Powered by a Purpose-Built VM and OS
Rust crates to extend containerd
Infrastructure for managed self-hosting
A containerd shim for running Spin Applications.
Signing-key abuse and update exploitation framework
Confidential Containers Guest Tools and Components
Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel and perform like containers, but provide the workload isolation and security advantages of VMs. https://katacontainers.io/
Rust library for the composefs filesystem
Process isolation for Linux using namespaces, resource limits, cgroups, landlock and seccomp.
Dragonfly client written in Rust
Open standard for mathematical programming interoperability
MicroVM Runtime
Build Software You Can Trust. Isolated, reproducible development environments and a secure package manager that give your whole team identical environments, while keeping AI agents off the laptop.