Главная
Study mode:
on
1
Introduction
2
Policy Spectrum
3
What is restricted
4
Unprivileged networking
5
How to address the problem
6
Running the workloads as normal
7
Security policies
8
Storage
9
Devices
10
Solution
11
Problem
12
File capabilities
13
File capabilities drawbacks
14
Cell Linux
15
Whats left
16
Outro
Description:
Explore the advancements in running KubeVirt workloads without additional privileges in this informative conference talk by Ľuboslav Pivarč from Red Hat. Dive into the journey of KubeVirt's evolution towards minimizing required capabilities for running virtual machines alongside containers on Kubernetes. Learn about the implementation of rootless user execution, seamless SELinux integration, and the challenges faced in achieving unprivileged networking. Discover the importance of considering security best practices when developing virtualization features, including the use of Linux Security Modules like SELinux and AppArmor. Gain insights into addressing issues related to storage, devices, and file capabilities, and understand the significance of Cell Linux in this context. Acquire valuable knowledge on enhancing security and efficiency in containerized and virtualized environments.

Running KubeVirt Workloads with No Additional Privileges

Linux Foundation
Add to list