Session
Rootless and Ruthless: Securing Containers without Root
Running containers as root has long been a security concern. Rootless containers promise a safer alternative, but how do they actually work? And what trade-offs do they introduce for developers and operators?
This talk dives into the mechanics of rootless containers, exploring user namespaces, filesystem mappings, and unprivileged mounts. We’ll compare runtimes like runc, crun, and gVisor to see how each approaches rootless execution. Then we’ll move to Kubernetes: how rootless pods integrate with clusters, what security guarantees they provide, and what performance costs they bring in networking, storage, and CPU scheduling.
By the end, you’ll know when rootless workloads are the right choice, how to debug them, and how to balance security with performance in production clusters.
Learning Outcomes
* Understand how user namespaces enable rootless execution.
* Compare rootless runtimes (runc, crun, gVisor).
* See how Kubernetes supports rootless pods.
* Evaluate performance vs security trade-offs.
* Gain strategies for adopting rootless workloads safely.
Target Audience
* Security-minded developers and DevOps engineers.
* Kubernetes practitioners adopting rootless workloads.
* Engineers curious about Linux namespaces and isolation.
Ajitem Sahasrabuddhe
Staff DevOps Engineer, Automattic
Nagpur, India
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top