October 4-6 in Berlin, Germany
Register Now for LinuxCon+ContainerCon Europe
Back To Schedule
Tuesday, October 4 • 15:30 - 16:20
User Namespace and Seccomp Support in Docker Engine - Paul Novarese, Docker

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Isolation in Docker is mainly accomplished via cgroups and namespaces. User namespaces are the newest namespace to be supported by the Docker engine, and allow users to run containers as without elevated privileges, which has been a longstanding shortcoming and frequent target of both user frustration and feature requests. In addition, Seccomp support adds a new method of containment for running containers by providing both whitelist and blacklist based controls of system calls that are permitted and/or forbidden for containerized processes. In this session, we’ll look at these new features, examine basics of configuration, and do some live demos to see them in action.

avatar for Paul Novarese

Paul Novarese

Technical Account Manager, Docker, Inc.
Paul has been working in the ops side of open source for over 20 years, providing technical support, training, and general consulting in both the largest and smallest data centers.

Tuesday October 4, 2016 15:30 - 16:20 CEST
Schinkel II/III