UKI, composefs and remote attestation for Bootable Containers

Presenters Timothée Ravier Pragyan Vitaly Kuznetsov Source All Systems Go! 2025 🚀 Securing the Future of Container Clusters: A Deep Dive into Secure Boot and Remote Attestation 🌐 The world of containerized applications is booming, but with that growth comes a critical need for robust security. Ever wondered how to guarantee that your container clusters boot up securely and haven’s been tampered with? A recent presentation explored a fascinating new approach using ComposerFS, offering a flexible and controlled alternative to traditional disk image-based systems. Let’s break down the key takeaways! ...

October 1, 2025 · 4 min

Unprivileged Containers, with Transient User Namespaces and ID Mapping, but Without SETUID Binaries

Presenters Lennart Poettering Source All Systems Go! 2025 🚀 Unveiling Transient UID Delegation: A New Era for Unprivileged Containers 🤖 The world of containerization is constantly evolving, and a recent presentation spotlighted a truly innovative approach: Transient UID Delegation. Forget the traditional complexities of subuid/subgid assignments – this new model focuses on providing temporary, on-demand UID ranges for containers, opening up exciting possibilities for enhanced security and simplified management. Let’s dive in! ...

October 1, 2025 · 3 min

oo7-daemon: One year later – Progress, Challenges, and What’s next

Presenters Dhanuka Warusadura Source All Systems Go! 2025 🚀 O7 Demon: The Future of Secret Service is Here! 🛠️ Hey everyone! 👋 Danuka recently gave a fascinating update on a project that’s poised to revolutionize how we handle secrets on our systems: O7 Demon. If you’re familiar with NOM keying, get ready for a change! This blog post will break down what O7 Demon is, what’s been accomplished, what’s still in progress, and how you can get involved. ...

September 30, 2025 · 4 min

How I optimized away 94% CPU from zbus

Presenters Zeeshan Ali Khan Source All Systems Go! 2025 🚀 ZBUS: Supercharging DBUS Communication in Rust ✨ DBUS. It’s a name that might evoke images of legacy systems and slightly dusty technology. But don’t count it out just yet! It’s a mature, widely-used inter-process communication (IPC) system, and when you need to talk between processes, it’s often a solid choice. But what happens when you want to do it fast? That’s where ZBUS comes in. This blog post dives into the fascinating story of how ZBUS, a Rust library, is revolutionizing DBUS communication. ...

September 30, 2025 · 3 min

Linux IPC: Lost between Threading and Networking

Presenters David Rheinsberg Source All Systems Go! 2025 🚀 Level Up Linux IPC: Lessons from the Trenches & a Call to Action 🛠️ Linux is the backbone of so much of our tech world, from servers to smartphones. But behind the scenes, something critical has been a source of frustration: inter-process communication (IPC). David’s recent presentation really dug into this, and we’re breaking down the issues, the inspiration, and a potential path forward. Buckle up – it’s a fascinating dive into the heart of operating system design! ...

September 30, 2025 · 4 min