Build · directory

The full directory

Every repository examined for this guide — including the ones that did not earn a chapter and the ones that are adjacent rather than sandboxes. Filter by family, platform, isolation model, network policy, credential handling and rating, or just search.

Reading the facets

Isolation is the boundary the project itself provides: os_sandbox means kernel process primitives, container means shared-kernel namespaces, microvm and vm mean a separate kernel, appkernel means a user-space kernel, wasm means a language runtime. Network and credentials describe what the project offers or assumes by default — host-side-injection is the credential-broker pattern and is the one you want. Ratings are the five categories used throughout the site; "unrated" means the project was catalogued but did not get a full assessment.

Every card includes a direct GitHub link. When a project publishes a separate homepage or documentation site, the card includes that too. External links are editorial references; they carry no referral or affiliate tracking.

Figures come from the GitHub API on the date shown in the footer and will drift. Star counts are displayed because they are interesting, not because they are evidence — see Risk Ratings for why.