Explore how systemd leverages eBPF to enhance security features in this 21-minute conference talk from KubeCon + CloudNativeCon Europe 2022. Dive into the recent integration of libbpf in systemd, which simplifies the development and maintenance of eBPF-based functionalities. Learn about two new security features implemented using this integration: RestrictFileSystems, which limits filesystem access for processes in systemd services, and RestrictNetworkInterfaces, which controls network interface usage. Gain insights into how these advancements improve the overall security and manageability of systemd-based systems.
Overview
Syllabus
Extending systemd Security Features with eBPF - Mauricio Vásquez Bernal, Microsoft
Taught by
CNCF [Cloud Native Computing Foundation]