Главная
Study mode:
on
1
Intro
2
Christian Brauner
3
Outline
4
What are containers
5
Limitations
6
syscalls
7
syscall conventions
8
seccomp
9
seccomp explained
10
syscall decision
11
kernel policy
12
intercept system calls
13
interception diagram
14
container manager
15
problems with syscall
16
race condition
17
demo
18
questions
19
security aspects
Description:
Explore the intricacies of unprivileged containers in this 54-minute conference talk by Christian Brauner from Canonical. Delve into the fundamentals of containers, their limitations, and the complexities surrounding syscalls. Gain insights into syscall conventions, seccomp, and kernel policies. Understand the process of intercepting system calls and the role of container managers. Examine common problems associated with syscalls, including race conditions, through practical demonstrations. Conclude with a discussion on critical security aspects, enhancing your knowledge of container technology and its practical applications.

Making Unprivileged Containers More Usable

Linux Foundation
Add to list