LinuxCommandLibrary
GitHubF-DroidGoogle Play Store

kern

rootless, daemonless OCI container and resource-slicing runtime

TLDR

Start an interactive Alpine shell
$ kern box dev --image alpine -it -- sh
copy
Cap a host process (no sandbox)
$ kern run --memory 256M --cpus 0.5 -- [./crunch]
copy
Run a service with port publish and restart
$ kern box svc --image nginx:alpine -d -p 8080:80 --restart -- nginx -g 'daemon off;'
copy
List running boxes
$ kern ps
copy
Exec into a box
$ kern exec [svc] -it -- sh
copy
Live TUI of CPU, memory, and volumes
$ kern top
copy
Bring up a Compose file (kern or Docker format)
$ kern compose [stack.toml] up
copy
Check whether this kernel can run boxes
$ kern doctor
copy

SYNOPSIS

kern command [options] [args]

DESCRIPTION

kern is a static ~1.5 MB Linux runtime: real OCI images, always-rootless namespaces (user, pid, mount, net, uts, ipc), seccomp, and cgroup v2, with no daemon. Cold start of a box from an image is a few milliseconds. Resource profiles in `~/.config/kern/kern.toml` (`vcpu:`, `vdisk:`, `vgpio:`) attach by name to either a box or kern run.`--security-profile untrusted` is the hardened bundle (seccomp allowlist, `--cap-drop ALL`, `--read-only`). It is not a hypervisor: a kernel LPE is an escape, same class as Docker/Podman.Python/Node kern-sandbox and kern-mcp wrap the same binary for agent-generated code.

COMMANDS

box name [options] -- cmd

Create/run an isolated box from an OCI image (`--image`, `-it`, `-d`, `-p`, `-v`, `--restart`, `--security-profile untrusted`, resource tokens like `vcpu:heavy`).
run [limits] -- cmd
Apply CPU/memory (and optional Landlock) to a process without a sandbox.
ps / logs / exec / stop / inspect / stats / wait
Lifecycle and inspection. Most list verbs also take --json.
top
Live TUI.
compose file up|down
Run `kern-compose.toml` or a `docker-compose.yml` as one pod.
doctor / validate
Host capability check and config validation.
volume, images, pull, build, commit, push, save, load
OCI and volume operations (see project docs for the full matrix).

CAVEATS

Linux only (WSL2 is fine; no native Windows). Needs unprivileged user namespaces and cgroup v2. Image pull wants curl and tar on PATH (and often pasta / uidmap for non-root images). Bind-mounting `$HOME` is a trust decision, not a boundary. Not a CRI runtime and not a Docker Engine API clone.

HISTORY

Apache-2.0 project by Alex / getkern. First published release v0.7.0. Install: `curl -fsSL https://raw.githubusercontent.com/getkern/kern/main/install.sh | sh` or `cargo install --git https://github.com/getkern/kern getkern --locked`.

SEE ALSO

podman(1), docker(1), bwrap(1), unshare(1)

RESOURCES

Braincup
Open source brain training for math, memory and focus
Braincup mini-games
41 mini-games · Apache-2.0
No ads · No tracking
Play in browser
Download Braincup on the App StoreGet Braincup on Google PlayGet Braincup on F-Droid
276 stars
From the maker of Linux Command Library
Copied to clipboard
Braincup
Open source brain training for math, memory and focus. 41 mini-games, from mental arithmetic to Sudoku, N-Back and Solo Chess.
Apache-2.0 licensed · No ads · No tracking · No account
From the maker of Linux Command Library
Download Braincup on the App StoreGet Braincup on Google PlayGet Braincup on F-Droid