Look ma, no secrets! - bootstrapping cryptographic trust in my homelab using Nix, UKIs, TPMs and SPI

Presenters Arian van Putten Source All Systems Go! 2025 🚀 Building a Self-Bootstrapping Home Lab: A Deep Dive into Automated Security 🛠️ Ever dreamt of a home lab that just… works? One where your servers configure themselves, establish secure connections, and generally take care of themselves without you constantly fiddling with manual configurations and risky secrets management? It’s a compelling vision, and one that a recent tech conference presentation brought to life – with a very dramatic live demo! Let’s break down how this ambitious project aims to achieve that goal. ...

September 30, 2025 · 5 min

systemd-confext Two Years On: Versioned Overlays for /etc, Reloaded

Presenters Maia Xiao Maanya Goenka Source All Systems Go! 2025 🚀 Level Up Your Linux Configuration Management with Confix! 🛠️ Managing configuration files on Linux systems, especially in dynamic environments like Azure, can be a real headache. It’s easy to introduce errors that can bring services crashing down. But what if there was a better way? Enter Confix, a new system designed to bring safer, more manageable configuration updates to your Linux world! Let’s dive in and explore how Confix can simplify your life. ...

September 30, 2025 · 3 min

BPF Tokens in systemd

Presenters Matteo Croce Source All Systems Go! 2025 🚀 Level Up Your Container Security with BPF Tokens! 🛠️ Containers have revolutionized how we build and deploy applications, offering incredible flexibility and efficiency. But with great power comes great responsibility – especially when it comes to security. Traditional methods for running Berkeley Packet Filter (BPF) programs within containers often required root privileges or the broad cap_bpf capability, which frankly, is a bit like giving everyone a master key to the kingdom. Thankfully, there’s a new sheriff in town: BPF Tokens! ...

September 30, 2025 · 3 min

A Security Model for systemd

Presenters Lennart Poettering Source All Systems Go! 2025 🚀 Leonard’s Security Vision: Reinventing System Security for the Future 🛠️ For decades, Unix and Linux have been the bedrock of modern computing. But as threats evolve, can these venerable systems truly keep pace? In a thought-provoking presentation, Leonard challenged fundamental assumptions about system security, advocating for a radical redesign that prioritizes isolation, measurement, and a rejection of legacy practices. This isn’t about patching vulnerabilities; it’s about fundamentally rethinking how we build secure systems. ...

September 30, 2025 · 4 min

The Hidden Vulnerability of The Open Source Software Supply Chain: The Underlying Infrastructure

Presenters Brian Fox Source InfoQ podcast Is Your Open Source Stack Under Attack? A Deep Dive into Supply Chain Security 🚨 The open-source world is the backbone of modern software, but a growing threat is lurking beneath the surface: malicious open-source components. A recent tech conference presentation shed light on this critical issue, and it’s a wake-up call for developers and organizations alike. Let’s unpack the challenges and explore practical solutions. ...

September 29, 2025 · 4 min