Karn helps to create profiles for applications. This is done with the available security mechanisms found on the system including AppArmor, capabilities, and seccomp.

By creating files in the TOML format, you tell the tool what an application can do. This could be for example stating which system calls are safe for that application. Karn then processes the TOML file and creates the related profiles.

Karn is commonly used for application security or system hardening.

Karn is under development by Grant Seltzer.

The bane tool is an AppArmor profile generator for Docker containers. It helps with creating the appropriate profile for confinement on system level.

