About this project
Kore is a web application platform for writing scalable, concurrent web-based processes in C or Python. It is designed with a "secure by default" approach and uses full privilege separation together with operating-system security features such as seccomp, pledge and unveil. The project reports use in areas including high-assurance cryptographic devices, machine-learning stacks and aerospace, and positions itself as suitable from embedded platforms up to high-performance servers.
Key capabilities listed by the project include SNI, HTTP/1.1 and WebSocket support, privilege separation by default, TLS enabled by default, optional background tasks, built-in parameter validation, optional asynchronous PostgreSQL support, optional Python page handlers, on-the-fly reloading of private keys and certificates, automatic X509 certificates via ACME with privilege separation, private keys isolated in a separate process for RSA and ECDSA, default TLS ciphersuites with forward secrecy, on-the-fly module reloading even while serving content, worker processes sandboxed on OpenBSD via pledge and on Linux via seccomp, an event-driven epoll/kqueue architecture with per-CPU worker processes, and the ability to build an application as a precompiled dynamic library or a single binary.
Kore is licensed under the ISC license. Documentation is available at docs.kore.io. Supported platforms are Linux, OpenBSD, FreeBSD and macOS, with x64, arm and aarch64 architectures only.
Building requires OpenSSL 1.1.1, LibreSSL 3.x or OpenSSL 3. Optional features have their own requirements: libcurl 7.64.0 or higher for asynchronous curl, pthreads for background tasks, libpq for PostgreSQL, Python 3.6+ for Python support, and Lua 5.4+ for Lua support. A normal build is done with make and make install. Optional build flavors are enabled through environment variables before running make: LUA=1, ACME=1, CURL=1, TASKS=1, PGSQL=1, DEBUG=1, NOHTTP=1, NOOPT=1, JSONRPC=1, PYTHON=1 and TLS_BACKEND=none. The README notes that some flavors cannot be combined and will produce compilation errors.
Example applications are provided under examples/, each with a README describing how to build or use it. The repository is described as a read-only mirror; contribution information points to the kore.io mailing lists, with patches@kore.io for patches and users@kore.io for questions, plus security@kore.io for security reports and sponsor@kore.io for sponsorship.
Comments
0 people shared their preference · Deer Point appears after 10 participants
Sign in to join the discussion.