Тёмный

Containers unplugged: understanding user namespaces - Michael Kerrisk 

NDC Conferences
Подписаться 193 тыс.
Просмотров 8 тыс.
50% 1

User namespaces are at the heart of many interesting technologies that allow isolation and sandboxing of applications, for example running containers without root privileges and sandboxes for web browser plug-ins.
In this presentation, we'll look in detail at user namespaces, building up a basic understanding of what a user namespace is and going on to questions such as: what does being “superuser inside a user namespace” allow you do (and what does it not allow); what is the relationship between user namespaces and other namespace types (PID, UTS, network, etc.); and what are the security implications of user namespaces? We'll also explore some simple shell commands that can be used for creating and experimenting with user namespaces in order to better understand how they work. Along the way, there will hopefully be time for a few live demos. You will likely find it helpful to attend my other presentation, "Linux namespaces", beforehand, but this is not essential.
Save the date for NDC TechTown 2020 (31st of August - 3rd of September)
Check out more of our talks at:
ndctechtown.com/
www.ndcconferences.com/

Наука

Опубликовано:

 

19 сен 2019

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 5   
@nasirmahmood7799
@nasirmahmood7799 3 года назад
best ever demonstration by someone who know things in details. lovely...v.v. lovely . I would like to listen these videos repeatedly.
@lucisetumbrae
@lucisetumbrae 2 года назад
Very much appreciate these talks about namespaces. Accelerated my understanding of Docker immensely.
@juvenjoson784
@juvenjoson784 3 года назад
good session explaining namespaces. best one I've seen that gave me a good insight how it works
@Ahmedhkad
@Ahmedhkad 2 года назад
I came here from docker docs to understand GID, UID , but just discovered that Linux without docker had the same and more thing for security, OMG I just want to know which docker container should get that number in PUID, PGID environment's option, and here I'm learning security stuff in Linux X)
@vimalk78
@vimalk78 Год назад
starts at 2:03
Далее
C++ Smart Pointers - Usage and Secrets - Nicolai Josuttis
1:02:22
Understanding user namespaces - Michael Kerrisk
53:30
How to Do 90% of What Plugins Do (With Just Vim)
1:14:03
Просмотров 870 тыс.
Linux Network Namespaces with ip netns
9:18
Просмотров 7 тыс.
Развод с OZON - ноутбук за 2875₽
17:48
Will the battery emit smoke if it rotates rapidly?
0:11
Самый СТРАННЫЙ смартфон!
0:57
Просмотров 32 тыс.