2026-10-24 –, Room 250
This talk explores how systemd-nspawn, a little-known but extremely versatile native process encapsulation subsystem for Linux, could be used as a resource-efficient and secure alternative to containers or virtualization as part of a privacy-conscious self-hoster's toolbox.
nspawns (a portmanteau of "namespace" and "spawn") are a built-in feature of the systemd startup manager that uses existing kernel-based process encapsulation technologies to implement FreeBSD jail-like functionality on Linux. In a way, it's something that would sit between Docker and chroots, combining the diverse configuration options of the former with the simplicity and flexibility of the latter. Surprisingly, considering how ubiquitous systemd is across most major Linux distributions, nspawns are a relatively obscure feature. In this talk, I will cover how I found my application for it as part of my journey of switching from cloud-based to on-premise self-hosting, along with what upsides and drawbacks I encountered while setting up an nspawn-based environment on a Red Hat-based system hooked to my own home LAN.
Tim "vulptronix" Knox is an aspiring software engineer new to the Seattle area. Their passion for computers and software development started from a young age, but making the switch to a small Linux distro in 2017 and figuring out how to manually get to an X session from a pitch black screen was the turning point in their life, as it led to them ultimately becoming a UNIX systems enthusiast. They have a knack for finding modern-day practical production-ready use for obscure, underrated or "old but gold" technology.