- docker
- https://github.com/google/gvisor
- https://github.com/google/nsjail
- https://github.com/netblue30/firejail (e.g. compiler-explorer uses this)
- https://podman.io/
- systemd-nspawn
- https://github.com/lxc/lxc
- https://github.com/lxc/lxd (not sure what's relation between lxc and lxd, seems like those are "one tool" in the end = client vs deamon)
- runc/binctr
- https://github.com/containers/bubblewrap
- sandstorm.io
- https://github.com/sylabs/singularity
- https://github.com/yandex/porto
- sio2jail
- https://github.com/google/sandboxed-api/tree/master/sandboxed_api/sandbox2
- Chromium's minijail - https://www.chromium.org/chromium-os/chromiumos-design-docs/system-hardening
- https://chromium.googlesource.com/chromiumos/platform/crosvm/
- https://github.com/firecracker-microvm/firecracker
- AppContainers - https://github.com/trailofbits/appjaillauncher-rs
- Apple sandbox (see also https://github.com/malus-security/sandblaster)