Overview
Explore the challenges and solutions of running systemd-based workloads in containers in this 45-minute conference talk from linux.conf.au 2022. Dive into the security features of Linux kernels and Kubernetes that enable better container isolation. Learn about namespaces, cgroups, and the behavior of systemd in containers as the speaker shares their journey of porting a complex legacy application to Kubernetes. Gain insights into container runtimes, OCI specifications, and the future of containerized systemd deployments. Expect demonstrations and a deep dive into the technical aspects of container security and orchestration.
Syllabus
Intro
Preliminaries
What is a container?
Containers on linux
Container standards
OCI Runtime Specification
Kubernetes - container orchestration
Kubernetes - terminology
Kubernetes - Pod definition
OpenShift - terminology
OpenShift runtime environment (today)
FreelPA on Kubernetes/OpenShift - use cases
Runtime user namespaces
Runtime - user namespaces - Kubernetes support
Runtime - OCI cgroup ownership semantics
Runtime - cluster configuration (OCP 4.10) - 3/3
Status and future
Taught by
linux.conf.au