For the privacy-conscious self-hoster, finding a balance between security, resource efficiency, and simplicity can be a challenge. This session explores systemd-nspawn, a versatile but often overlooked native process encapsulation subsystem for Linux that serves as a middle ground between Docker and chroots. By leveraging kernel-based process encapsulation to implement FreeBSD jail-like functionality, nspawn provides a lightweight alternative to traditional containers or virtualization. The speaker will share their journey of switching from cloud-based to on-premise self-hosting, detailing the specific upsides and drawbacks of implementing an nspawn-based environment on a Red Hat-based system.
Target Audience: