BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.devconf.info//devconf-cz-2026//talk//WNQEYL
BEGIN:VTIMEZONE
TZID:CET
BEGIN:STANDARD
DTSTART:20001029T040000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-devconf-cz-2026-WNQEYL@pretalx.devconf.info
DTSTART;TZID=CET:20260618T131500
DTEND;TZID=CET:20260618T135000
DESCRIPTION:How do we provide platform engineers and security architects wi
 th the same immutability and integrity for the operating system (OS) that 
 they expect from containers? While OSTree pioneered transactional deployme
 nts\, the ecosystem has shifted toward OCI images and sealed\, hardware-ro
 oted attestation\, leaving a gap for a standardized\, verifiable OS delive
 ry path.\n\nThis talk introduces a shift in image-mode Linux\, aligning th
 e OS directly with the OCI model using bootc and composefs. By consuming O
 CI images and materializing them through composefs\, we create a bootable\
 , verifiable filesystem with strong lifecycle and update guarantees.\n\nWe
  compare this approach with traditional OSTree methods\, examining layerin
 g\, updates\, and operational trade-offs. We will demonstrate deploying a 
 composefs-backed system on Fedora 44.\n\nAfter this talk\, attendees will 
 be ready to build\, verify\, and deploy OCI-native operating systems with 
 production-grade integrity.
DTSTAMP:20260430T124923Z
LOCATION:E112 (capacity 156)
SUMMARY:Hardening Operating System Distribution: Verifiable and sealed OS w
 ith bootc and composefs - Colin Walters
URL:https://pretalx.devconf.info/devconf-cz-2026/talk/WNQEYL/
END:VEVENT
END:VCALENDAR
