1 of 88

Container Linux on the Desktop

Or How I Over Engineered My Laptop

2 of 88

I am Jess

2

3 of 88

I have contributed to many

open source projects including

Docker, Go, Kubernetes,

Runc, & the Linux kernel

3

4 of 88

Content Warning for the rest of this talk

DO NOT TRY THIS AT HOME

5 of 88

Content Warning for the rest of this talk

No really, don’t

6 of 88

Content Warning for the rest of this talk

I mean it….

7 of 88

Content Warning for the rest of this talk

And if you do,

DO NOT COME TO ME FOR SUPPORT

8 of 88

I have done some things with containers.

9 of 88

10 of 88

I containerized my closet.

11 of 88

How this all started...

12 of 88

October 2014…

Young Jess

13 of 88

Things I have demoed in containers...

  • Steam
  • OpenGL applications
  • Chrome
  • Skype
  • Text User Interfaces (TUIs)
  • Pretty much anything….

14 of 88

This is all fine and dandy but can we build a secure OS from it....

15 of 88

Secure OS Base - CoreOS Container Linux

rootless app container with seccomp

rootless app container with seccomp

rootless app container with seccomp

rootless app container with seccomp

16 of 88

I also have a thing for sandboxes...

16

17 of 88

What is a sandbox?

17

18 of 88

18

19 of 88

Provides a net reduction in attack surface.

19

20 of 88

Compare code execution from inside and outside the sandbox...

Are more or less things possible now?

20

21 of 88

Compare code execution from inside and outside the sandbox...

Are more or less things possible now?

21

22 of 88

Chrome Sandbox

22

23 of 88

Each tab gets its own pid namespace.

23

24 of 88

What’s a pid namespace?

Used to isolate the process ID number space.

24

25 of 88

Also uses unprivileged user namespaces and network namespaces.

25

26 of 88

Uses Seccomp-BPF

26

27 of 88

27

28 of 88

What is Seccomp?

28

29 of 88

SECure COMPuting with filters

29

30 of 88

Allows developers to write BPF programs that determine whether a given system call will be allowed or not.

30

31 of 88

What is BPF?

Berkeley Packet Filter

In-kernel bytecode machine that is used for tracing, virtual networks, seccomp… and more.

31

32 of 88

Let’s apply these same principles to containers...

33 of 88

34 of 88

Docker's default seccomp profile is a whitelist which specifies the calls that are allowed.

34

35 of 88

It blocks a bunch of bad stuff…

(not limited to the following)

35

36 of 88

add_key

keyctl

request_key

Prevent containers from using the kernel keyring, which is not namespaced.

36

37 of 88

clone

Deny cloning new namespaces.

Also gated by CAP_SYS_ADMIN for CLONE_* flags, except CLONE_USERNS, which is a big one to block by default :D

37

38 of 88

unshare

Deny cloning new namespaces for processes. Also gated by CAP_SYS_ADMIN, with the exception of unshare --user.

38

39 of 88

In making this default seccomp profile I broke my desktop...

40 of 88

Running Chrome in a container requires a custom profile because of this...

41 of 88

Remaining

Problems

docker daemon runs as root

42 of 88

43 of 88

44 of 88

Mad props to Aleksa Sarai because that patch took over a year to merge.

45 of 88

Working with runc...

46 of 88

Previous I used docker for my containers so I had to convert all the configs...

47 of 88

48 of 88

And what about networking...

49 of 88

50 of 88

So at this point we...

Have ability to sandbox desktop apps by running them in containers

Can run the containers _not_ as root to eliminate needing privileges

51 of 88

CoreOS Container Linux

51

52 of 88

read-only /usr and stateful read/write /

53 of 88

Forces the use of containers.

54 of 88

Auto-updates

(If I wanted to host my own Omaha server which I am not that crazy yet)

55 of 88

Trusted Computing with TPM

56 of 88

dm-verity

57 of 88

I get all these things out of the box by using Container Linux as an OS base.

58 of 88

Just had to add graphics drivers.

59 of 88

Emerge all the way down :)

60 of 88

Building Container Linux

60

61 of 88

Repos all the way down

62 of 88

scripts

Build and maintenance scripts.

63 of 88

init

Init system unit files and config files.

64 of 88

coreos-overlay

Portage overlay for specific coreos packages, custom ebuilds.

65 of 88

manifest

Configuration files for pulling all the repos together. Used by repo tool.

Pretty much the ultimate source of truth.

66 of 88

manifest

<project path="src/platform/factory-utils"

name="chromiumos/platform/factory-utils"

groups="minilayout" remote="cros" />

<project path="src/scripts"

name="jessfraz/scripts"

revision="desktop"

groups="minilayout" />

<project path="src/third_party/portage-stable"

name="jessfraz/portage-stable"

revision="desktop"

groups="minilayout" />

<project path="src/third_party/coreos-overlay"

name="jessfraz/coreos-overlay"

revision="desktop"

groups="minilayout" />

67 of 88

baselayout

Base Container Linux filesystem layout and configs.

68 of 88

portage-stable

Mirror of ebuilds from portage tree.

69 of 88

mantle

Tool to build Container Linux images. Uses a chroot, super nice to use.

70 of 88

Image Building Pipeline

70

71 of 88

I run everything in containers...

72 of 88

So you can imagine I have quite a few container images...

73 of 88

74 of 88

75 of 88

76 of 88

77 of 88

78 of 88

79 of 88

Secure OS Base - CoreOS Container Linux

rootless app container with seccomp

rootless app container with seccomp

rootless app container with seccomp

rootless app container with seccomp

80 of 88

Secure OS Base - CoreOS Container Linux

rootless app container with seccomp

rootless app container with seccomp

rootless app container with seccomp

rootless app container with seccomp

git push & cron

81 of 88

Secure OS Base - CoreOS Container Linux

rootless app container with seccomp

rootless app container with seccomp

rootless app container with seccomp

rootless app container with seccomp

Jenkins CI

git push & cron

82 of 88

Secure OS Base - CoreOS Container Linux

rootless app container with seccomp

rootless app container with seccomp

rootless app container with seccomp

rootless app container with seccomp

Jenkins CI

git push & cron

build , push, and sign images

83 of 88

Secure OS Base - CoreOS Container Linux

rootless app container with seccomp

rootless app container with seccomp

rootless app container with seccomp

rootless app container with seccomp

Jenkins CI

git push & cron

build , push, and sign images

scans image for vulns

84 of 88

So now we have...

  • A secure base OS with dm-verity, trusted boot, simple filesystem, read-only /usr, and auto-updates
  • Sandboxed applications in containers not running as root
  • Container images that get updates and scanned for vulnerabilities regularly

85 of 88

Secure OS Base - CoreOS Container Linux

rootless app container with seccomp

rootless app container with seccomp

rootless app container with seccomp

rootless app container with seccomp

86 of 88

Oh btw this entire talk has been running on Container Linux ;)

87 of 88

In a rootless container with a seccomp filter.

88 of 88

Thank you!

@jessfraz