Making Unprivileged Containers More Usable
Offered By: Linux Foundation via YouTube
Course Description
Overview
Explore the intricacies of unprivileged containers in this 54-minute conference talk by Christian Brauner from Canonical. Delve into the fundamentals of containers, their limitations, and the complexities surrounding syscalls. Gain insights into syscall conventions, seccomp, and kernel policies. Understand the process of intercepting system calls and the role of container managers. Examine common problems associated with syscalls, including race conditions, through practical demonstrations. Conclude with a discussion on critical security aspects, enhancing your knowledge of container technology and its practical applications.
Syllabus
Intro
Christian Brauner
Outline
What are containers
Limitations
syscalls
syscall conventions
seccomp
seccomp explained
syscall decision
kernel policy
intercept system calls
interception diagram
container manager
problems with syscall
race condition
demo
questions
security aspects
Taught by
Linux Foundation
Tags
Related Courses
Cloud Computing Applications, Part 1: Cloud Systems and InfrastructureUniversity of Illinois at Urbana-Champaign via Coursera Introduction aux conteneurs
Microsoft Virtual Academy via OpenClassrooms Elastic Cloud Infrastructure: Containers and Services
Google Cloud via Coursera Architecting Distributed Cloud Applications
Microsoft via edX DevOps Practices and Principles
Microsoft via edX