Loading…
Type: Lightning Talk clear filter
Thursday, August 28
 

13:35 CEST

Monitoring filesystems with fanotify inside containers - Amir Goldstein, CTERA Networks
Thursday August 28, 2025 13:35 - 13:50 CEST
Filesystem monitoring was added to fanotify in kernel 5.1
and the first HSM feature was added to fanotify in kernel 6.12.
See this Linux Plumbers talk by fanotify maintainer Jan Kara for a
good overview:
https://lpc.events/event/18/contributions/1717/attachments/1648/3404/fanotify.pdf

This talk will present our work towards making those features available inside containers using two different strategies:

1. For filesystems that were mounted inside userns or idmapped into userns, userns admin would be able to use fanotify to monitor those filesystems.

2. For filesystems that were mounted by the host, container users would be able to subscribe to a service on the host to receive filesystem monitoring events contained to the scope of the container.
Speakers
avatar for Amir Goldstein

Amir Goldstein

Principal Software Engineer, CTERA Networks
Filesystem developer with affection for open source projects._x000D_ _x000D_ Lead technology groups at various start-up companies in the fields of Security, Filesystems, Networking and Virtualization._x000D_ _x000D_ Prominent fanotify developer and lead of fanotify HSM API project._x000D_... Read More →
Thursday August 28, 2025 13:35 - 13:50 CEST
TBA

13:50 CEST

urunc: A container runtime for unikernels and single application kernels - Charalampos Mainas, Nubis PC
Thursday August 28, 2025 13:50 - 14:05 CEST
Traditional container runtimes rely on OS-level isolation using namespaces and cgroups. While efficient, this approach can fall short in multi-tenant environments where stronger workload isolation is essential. To mitigate these risks, containers execute within sandboxes, often in the form of VMs. However, this approach typically involves extra components to manage the container lifecycle within the VM, adding complexity and increasing resource usage.

What if we could have the best of both worlds, strong isolation and low overhead? The key lies in specialization! Unikernels and
stripped-down Linux VMs, tailored for a single application, offer VM-grade isolation with small resource usage and fast boot times.

This talk introduces urunc, a novel container runtime that makes this approach practical. Urunc reverses the traditional model: instead of running containers inside VMs, it runs lightweight VMs, as containers. CRI-compatible, urunc integrates seamlessly with Kubernetes, enabling the orchestration of such VMs just like regular containers. The talk covers the design and architecture of urunc, its key differences with other sandboxing technologies and includes a live demo.

Speakers
avatar for Charalampos Mainas

Charalampos Mainas

Software Systems Engineer, Nubis PC
Charalampos Mainas is a systems engineer who is very interested in virtualization technologies and operating systems. His main focus is on finding ways to improve the performance and scalability of lightweight VMMs. Moreover, he has considerable experience with unikernel stacks, porting... Read More →
Thursday August 28, 2025 13:50 - 14:05 CEST
TBA

14:05 CEST

Skiff - OCI image analysis utility - Danish Prakash & Dan Čermák, SUSE
Thursday August 28, 2025 14:05 - 14:20 CEST
Container Images are foundational to modern infrastructure, yet their internal structure can often be opaque and difficult to debug. Large image sizes, hidden redundant files, and inefficient layering can lead to slower deployments and wasted resources. Manually dissecting layers or understanding disk usage across an image stack is often cumbersome and time-consuming.

This lightning talk introduces skiff, a powerful command-line utility designed to simplify OCI image introspection. Built using podman's container libraries, skiff provides developers and operators with tooling to introspect image layers. We will demonstrate how skiff can be used for the following tasks:
- Identify large layers and files
- Explore layer contents directly
- Visualize disk usage
- Locate whiteout files

Join this session to learn how skiff can help you analyze, debug, and optimize container images for better performance and resource utilization.
Speakers
avatar for Dan Čermák

Dan Čermák

Senior Full Stack Web Developer, SUSE
Dan is working as a Senior Web developer, building container images, creating developer tools and sometimes works on QA at SUSE, which he joined after working as an embedded firmware developer. Originally he started out as a theoretical astrophysicist, but after becoming a contributor... Read More →
avatar for Danish Prakash

Danish Prakash

Software Engineer, SUSE
Danish Prakash is a Container Engine Engineer at SUSE. He is a contributor to upstream projects such as Podman, Buildah, nerdctl, etc, and is the downstream maintainer of these packages for SUSE Linux products.
Thursday August 28, 2025 14:05 - 14:20 CEST
TBA

14:20 CEST

Atomic OS Updates via OCI Images: Introducing container-snap - Dan Čermák, SUSE
Thursday August 28, 2025 14:20 - 14:35 CEST
When using tools like RPM or Zypper for updating packages, there is a risk of incomplete updates or breaking the running system. To overcome these challenges, we have developed container-snap, a prototype plugin designed to deliver atomic OS updates that are fully applied or rolled back without compromising the system's state.

container-snap leverages OCI images as the source for updates and integrates seamlessly with openSUSE’s tukit for transactional OS updates. By utilizing Podman’s btrfs storage driver, it creates bootable btrfs subvolumes directly from OCI images, effectively turning them into atomic OS snapshots. This allows you to build OS images using familiar tools like Docker or Buildah and deploy the container image on your host.

This lightning talk covers the following topics:
- The container-snap architecture and implementation details
- Main development challenges and solutions
- Lessons learned in bridging container tech and OS updates
- A live demo showcasing atomic updates in action

Join this session to learn more about how to boot from an OCI image without bricking your system!
Speakers
avatar for Dan Čermák

Dan Čermák

Senior Full Stack Web Developer, SUSE
Dan is working as a Senior Web developer, building container images, creating developer tools and sometimes works on QA at SUSE, which he joined after working as an embedded firmware developer. Originally he started out as a theoretical astrophysicist, but after becoming a contributor... Read More →
Thursday August 28, 2025 14:20 - 14:35 CEST
TBA
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.