Yocto's hidden gem: OTA and seamless updates with systemd-sysupdate

Presenters Emmanuele Bassi Martín Abente Lahaye Source All Systems Go! 2025 🚀 Level Up Your Embedded Systems: Integrating System CIS Updates with Yocto 🛠️ Building custom Linux-based operating systems for embedded devices can feel like a monumental task. You need flexibility, control, and most importantly, a robust update mechanism. That’s where Yocto and System CIS Updates come into play! Emanuel from Egalia recently gave a fantastic presentation diving deep into how these two powerhouses can work together, and we’ve broken down the key takeaways for you. ...

October 1, 2025 · 4 min

UKI, composefs and remote attestation for Bootable Containers

Presenters Timothée Ravier Pragyan Vitaly Kuznetsov Source All Systems Go! 2025 🚀 Securing the Future of Container Clusters: A Deep Dive into Secure Boot and Remote Attestation 🌐 The world of containerized applications is booming, but with that growth comes a critical need for robust security. Ever wondered how to guarantee that your container clusters boot up securely and haven’s been tampered with? A recent presentation explored a fascinating new approach using ComposerFS, offering a flexible and controlled alternative to traditional disk image-based systems. Let’s break down the key takeaways! ...

October 1, 2025 · 4 min

A terminal for operating clouds: administering S3NS with image-based NixOS

Presenters Ryan Lahfa Frederic Ruget Gautier LABADIE Source All Systems Go! 2025 🚀 Building a Secure Workstation: Lessons from Google’s S3S Team 💡 The pursuit of a truly secure and reliable workstation is a challenging one. It’s a constant balancing act between idealism and practicality, between the dream of a perfectly reproducible system and the realities of user needs and technical constraints. Recently, the S3S (Secure Systems) team at Google Cloud shared their journey in building a secure workstation environment, and the insights they’re gaining are incredibly valuable. Let’s dive in! ...

October 1, 2025 · 4 min

Introducing ue-rs, minimal and secure rewrite of update engine in Flatcar

Presenters Dongsu Park Source All Systems Go! 2025 🚀 Revamping OS Updates: A Deep Dive into Fleck’s Rust Rewrite 🛠️ Keeping your operating system secure and up-to-date is crucial, but the underlying mechanics can be surprisingly complex. Today, we’re diving into a fascinating project: Fleck’s rewrite of its update engine in Rust. This isn’t just about writing new code; it’s about fundamentally rethinking how we handle OS updates, prioritizing security, minimalism, and maintainability. Let’s explore this journey! ...

October 1, 2025 · 4 min

container-snap: Atomic Updates from OCI Images using Podman’s Btrfs Driver

Presenters Dan Čermák Source All Systems Go! 2025 🚀 Atomic Updates: A Glimpse into the Future of System Management 💾 Let’s face it: we’ve all been there. It’s Friday night, you scheduled those crucial system updates, and then… disaster. A failed update leaves your system in a half-baked, inconsistent state, kicking off a frantic emergency intervention. Dan’s presentation at the conference offered a fascinating look at a potential solution – a system where updates are atomic – meaning they either succeed completely or roll back cleanly. Let’s dive in! ...

October 1, 2025 · 4 min