Unprivileged Containers, with Transient User Namespaces and ID Mapping, but Without SETUID Binaries

Presenters Lennart Poettering Source All Systems Go! 2025 🚀 Unveiling Transient UID Delegation: A New Era for Unprivileged Containers 🤖 The world of containerization is constantly evolving, and a recent presentation spotlighted a truly innovative approach: Transient UID Delegation. Forget the traditional complexities of subuid/subgid assignments – this new model focuses on providing temporary, on-demand UID ranges for containers, opening up exciting possibilities for enhanced security and simplified management. Let’s dive in! ...

October 1, 2025 · 3 min

Shipping Flatpak applications with an image based system

Presenters Abderrahim Kitouni Source All Systems Go! 2025 🚀 Pre-Installed Apps in Gnome OS: Navigating the Flatpak Frontier 🌐 Gnome OS aims to deliver a smooth, user-friendly experience, and a key ingredient in that is having essential applications readily available. But how do you pre-install those apps while staying true to the core principles of Flatpak – namely, sandboxing and consistency? This presentation delved deep into this challenge, exploring various solutions and their trade-offs. Let’s break down the problem and the proposed approaches. ...

October 1, 2025 · 3 min

oo7-daemon: One year later – Progress, Challenges, and What’s next

Presenters Dhanuka Warusadura Source All Systems Go! 2025 🚀 O7 Demon: The Future of Secret Service is Here! 🛠️ Hey everyone! 👋 Danuka recently gave a fascinating update on a project that’s poised to revolutionize how we handle secrets on our systems: O7 Demon. If you’re familiar with NOM keying, get ready for a change! This blog post will break down what O7 Demon is, what’s been accomplished, what’s still in progress, and how you can get involved. ...

September 30, 2025 · 4 min

From initramfs-tools to mkosi-initrd

Presenters Marco d'Itri Source All Systems Go! 2025 🚀 Can MKOSI Replace Debian’s Init System? A Deep Dive 🛠️ For those unfamiliar, the init system is the very first process that runs when an operating system boots. It’s the foundation upon which everything else is built. Debian, a popular Linux distribution, currently relies on a collection of shell scripts and packages for its init system. But what if we could replace it with something new, like MKOSI? Let’s explore the journey, the challenges, and the potential rewards. ...

September 30, 2025 · 4 min

A new systemd container runtime?!

Presenters Daan De Meyer Source All Systems Go! 2025 🚀 Systemd & Containers: A New Era of Portable & Secure Workflows 🛠️ The world of containers is constantly evolving, and Systemd, the ubiquitous Linux system and service manager, is right in the thick of it. Recently, a fascinating presentation delved into Systemd’s ambitious plans to redefine containerization, focusing on enhanced security, portability, and integration with the Open Container Initiative (OCI). Let’s break down the key takeaways – no need to worry, we’re making this complex topic easy to digest! ...

September 30, 2025 · 4 min