"Microsoft Azure Boost: Image-based Linux powering the Azure fleet", a deep dive into a tailored Linux distro focused on security that provides offloading and acceleration. A great talk by @bluca at @allsystemsgo!
A lot of stuff is introduced: Linux hardening, remote attestation, SELinux, dm-verity, IPE, LUKS, fs-verity, overlayfs, systemd portable services, soft reboot, ARM, FPGA, DPDK...
Slides: https://cfp.all-systems-go.io/all-systems-go-2023/talk/7URRNC/
Recording: https://youtu.be/iB-wRdC8zNs
"#Landlock Workshop: Sandboxing Application for Fun and Protection" at #linuxsecuritysummit Europe: https://sched.co/1OLAi
A practical sandboxing use case illustrated with the #ImageTragick vulnerability. All you need to build, test and patch: https://github.com/landlock-lsm/workshop-imagemagick
The conference will start soone. You can follow it here:
https://www.youtube.com/watch?v=PSS9VemnSkg
Enjoy!
The Kernel Recipes Live Blog is going at full steam #kr2023 https://kernel-recipes.org/en/2023/live-blog-day-1-morning/
We recently added a new document to the systemd website focussing on one specific facet of the service manager: the fdstore. A concept that people should really use more to facilitate "seamless" service restarts and various other things. Please have a look:
I'm very excited to announce that you can now try #Incus online!
The new demo environment uses Incus virtual machines running on a remote Incus cluster with full support for both containers and VMs!
https://linuxcontainers.org/incus/try-it/