// the find
jorisvink/kore
An easy to use, scalable and secure web application framework for writing web APIs in C or Python. || This is a read-only mirror, please see https://kore.io/mail and https://kore.io/source for information on how to contribute via the mailing lists.
Kore is a C (and optionally Python) web framework for writing HTTP services as privilege-separated worker processes, built around epoll/kqueue and designed to be secure by default rather than secure if configured correctly. It's for people who want C-level performance and control but don't want to hand-roll TLS, privsep, and sandboxing themselves — think embedded devices, crypto appliances, or anyone already committed to a C stack.
Privilege separation and OS-level sandboxing (seccomp on Linux, pledge/unveil on OpenBSD) are baked into the worker model, not bolted on — that's rare in web frameworks regardless of language. TLS is on by default with sane cipher suites and supports ACME renewal with keys isolated in a separate process, so you don't accidentally ship plaintext HTTP or weak ciphers. The per-CPU worker, event-driven architecture with on-the-fly module reload (swap code without dropping connections) is a genuinely useful operational feature most frameworks don't offer.
This is a read-only GitHub mirror — no issues, no PRs, contribution only via mailing list patches, which filters out most casual contributors and makes the GitHub star count a poor proxy for how active development actually is. It's still C: built-in parameter validation helps at the HTTP boundary but doesn't protect you from the memory-safety bugs you'll inevitably write in your own handlers. Python support is explicitly secondary (compile-time flag, smaller surface in the docs) so don't expect feature parity with the C side. The examples directory covers the basics but there's no visible plugin/module ecosystem, so anything beyond what's in core you're writing yourself.