Security by Compartmentalization

Operating systems:

Experiments:

Tools:

  • libkrun - A dynamic library providing Virtualization-based process isolation capabilities
    • muvm - run programs from your system in a microVM
  • MicroVM.nix - NixOS MicroVMs

Casual

Network devices (firmware)

NAS / self-hosting OS:

Android-like