Unprivileged Containers, with Transient User Namespaces and ID Mapping, but Without SETUID Binaries (asg2025) episode artwork

EPISODE · Oct 1, 2025 · 41 MIN

Unprivileged Containers, with Transient User Namespaces and ID Mapping, but Without SETUID Binaries (asg2025)

from Chaos Computer Club - recent events feed · host Lennart Poettering

Many traditional container engines make use of the "subuid" concept and the "newuidmap" tool to implement a concept of "unprivileged" user-namespace containers on Linux. This approach has many shortcomings in my PoV, from both a security and scalability standpoint. Recent systemd versions provide a more powerful, more secure, mor scalable alternative, via systemd-nsresourced, systemd-mountfsd and other components. In this talk I want to shed some light on the problems with the "old ways", and in particular focus on what the "new ways" bring to the table, and how to make use of them in container runtimes. Licensed to the public under https://creativecommons.org/licenses/by/4.0/de/ about this event: https://cfp.all-systems-go.io/all-systems-go-2025/talk/E7FHPY/

Episode metadata supplied by the publisher feed · Published Oct 1, 2025

Embed this episode

NOW PLAYING

Unprivileged Containers, with Transient User Namespaces and ID Mapping, but Without SETUID Binaries (asg2025)

0:00 41:53

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Chaos Computer Club - recent events feed?

This episode is 41 minutes long.

When was this Chaos Computer Club - recent events feed episode published?

This episode was published on October 1, 2025.

Can I download this Chaos Computer Club - recent events feed episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!