UKI, composefs and remote attestation for Bootable Containers

Presenters Timothée Ravier Pragyan Vitaly Kuznetsov Source All Systems Go! 2025 🚀 Securing the Future of Container Clusters: A Deep Dive into Secure Boot and Remote Attestation 🌐 The world of containerized applications is booming, but with that growth comes a critical need for robust security. Ever wondered how to guarantee that your container clusters boot up securely and haven’s been tampered with? A recent presentation explored a fascinating new approach using ComposerFS, offering a flexible and controlled alternative to traditional disk image-based systems. Let’s break down the key takeaways! ...

October 1, 2025 · 4 min

A terminal for operating clouds: administering S3NS with image-based NixOS

Presenters Ryan Lahfa Frederic Ruget Gautier LABADIE Source All Systems Go! 2025 🚀 Building a Secure Workstation: Lessons from Google’s S3S Team 💡 The pursuit of a truly secure and reliable workstation is a challenging one. It’s a constant balancing act between idealism and practicality, between the dream of a perfectly reproducible system and the realities of user needs and technical constraints. Recently, the S3S (Secure Systems) team at Google Cloud shared their journey in building a secure workstation environment, and the insights they’re gaining are incredibly valuable. Let’s dive in! ...

October 1, 2025 · 4 min

Leveraging bootable OCI images in Fedora CoreOS and RHEL CoreOS

Presenters Jonathan Lebon Timothée Ravier Source All Systems Go! 2025 🚀 Fedora’s Bold Move: Bootable Containers for a Faster, More Reliable Future 🌐 Fedora is embarking on a fascinating and ambitious journey: transitioning to a system based on bootable containers. This isn’t your typical containerization – we’re not talking about running full operating systems inside containers. Instead, Fedora is reimagining how the entire root filesystem is managed and updated, and the implications are huge! Let’s dive into what this means and why it’s a game-changer. ...

October 1, 2025 · 4 min

container-snap: Atomic Updates from OCI Images using Podman’s Btrfs Driver

Presenters Dan Čermák Source All Systems Go! 2025 🚀 Atomic Updates: A Glimpse into the Future of System Management 💾 Let’s face it: we’ve all been there. It’s Friday night, you scheduled those crucial system updates, and then… disaster. A failed update leaves your system in a half-baked, inconsistent state, kicking off a frantic emergency intervention. Dan’s presentation at the conference offered a fascinating look at a potential solution – a system where updates are atomic – meaning they either succeed completely or roll back cleanly. Let’s dive in! ...

October 1, 2025 · 4 min

Dirlock: a new tool to manage encrypted filesystems

Presenters Alberto Garcia Source All Systems Go! 2025 🚀 Level Up Your Linux Security with Dlock: A Deep Dive 💾 Are you looking for more granular control over your Linux system’s security? Do you want to move beyond simple password-based encryption? Then you’re in the right place! We’re diving into a fascinating new tool called Dlock, a project designed to bring enhanced full-disk encryption (FDE) capabilities to Linux, particularly for devices like the Steam Deck. Let’s explore what it is, how it works, and what the future holds. ...

October 1, 2025 · 4 min