Skip to main content

ParticleOS, from Fedora to Feast: Stirring Traditional Distros into Immutable Delights

UB2.147 | Day 2 | 15:30 - 15:55 | Speakers: Luca Boccassi

ParticleOS, from Fedora to Feast: Stirring Traditional Distros into Immutable Delights
A picture of a devroom at FOSDEM 2024
Open in browser

Notes

Abstract

How to successfully brew a Linux immutable image, with bells and whistles

Creating a (truly!) immutable distribution with a strong security posture and a chain of trust that starts in the hardware and ends in userspace is no longer a job that requires an entire team and starting from first principles. With the power of tooling and infrastructure provided by the systemd project, anyone can customize, build and deploy at scale and securely starting from your preferred traditional package-based distribution.

This talk will go over all the tooling and infrastructure available to achieve this, from systemd to mkosi, from UEFI Secure Boot and dm-verity to the Integrity Policy Enforcement LSM, from OBS to systemd-sysupdate, from systemd-repart to systemd-firstboot, and show a working example and how to reproduce and customize it.

Attachments


Notice: The placeholder video image is licensed under CC BY-SA 4.0. The original image can be found hereChanges made to the image are: Cropped the image to a new ratio, part of the image was cut off.