Speaker
Description
It is becoming really common for users and developers to have to download and install tools directly from the network and just run them on their systems. To some extent this has always been the case, and there is a degree of trust implied when downloading binaries, particularly now with the all too common "curl-to-shell" installs.
This talk presents a few CLI tools providing simple basic isolated environments: primarily using Linux containers. In particular the author's experiments with his encapsule project will be described and shown, built on top of Podman. It is a restricted Toolbox-like environment that provides a simple way to only expose specific files and system access to such a downloaded tool, which is something he had wanted for quite some time.
Talk Description
This is a mildly technical talk which assumes a little understanding of Linux containers.
The main points in the topic covered will be:
- the need for isolation tools
- different approaches: chroots, containers and VMs
- early examples
- Toolbox vs Encapsule
- detailed technical description of Encapsule and what it provides
- briefly cover other tools like OpenShell and Litterbox
I intend to include some short demos.
The audience should gain a clear understanding of the need to consider and use isolation of tools to protect the privacy and security of their system and files.
I think the talk could be either 30 or 50 minutes, depending on the program schedule.
Author(s) Bio
Jens Petersen has been involved in Software Engineering at Red Hat since the beginning of Fedora and RHEL,
| Category | Application Development and Deployment |
|---|---|
| Twitter and/or Mastodon Handle | juhp |
| Where are you located? | Singapore |
| Do you need travel sponsorship from GNOME Foundation in order to join our event? | No |