SC2021Top-tier venue
Minimizing privilege for building HPC containers
Reid Priedhorsky, Shane Richard Canon, Timothy Randles, Andrew J. Younge
Abstract
HPC centers face increasing demand for software flexibility, and there is growing consensus that Linux containers are a promising solution. However, existing container build solutions require root privileges and cannot be used directly on HPC resources. This limitation is compounded as supercomputer diversity expands and HPC architectures become more dissimilar from commodity computing resources. Our analysis suggests this problem can best be solved with low-privilege containers. We detail relevant Linux kernel features, propose a new taxonomy of container privilege, and compare two open-source implementations: mostly-unprivileged rootless Podman and fully-unprivileged Charliecloud. We demonstrate that low-privilege container build on HPC resources works now and will continue to improve, giving normal users a better workflow to securely and correctly build containers. Minimizing privilege in this way can improve HPC user and developer productivity as well as reduce support workload for exascale applications.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b91c39be-c201-4728-8748-d141957930efCited by top-tier papers2
- Exploring the Use of WebAssembly in HPCMohak Chadha, Nils Krueger, Jophin John, Anshul Jindal et al.PPoPP 2023 · 16 citations
- coMtainer: Compilation-assisted HPC Container Images with Enhanced AdaptabilityYuhao Gu, Haoquan Chen, Xianjie Chen, Jiangsu Du et al.SC 2025 · 1 citation
Builds on1
Related papers
- XaaS Containers: Performance-Portable Representation With Source and IR ContainersMarcin Copik, Eiman Alnuaimi, Alok Kamatar, Valérie Hayot-Sasson et al.SC 2025 · 2 citations
- Losing the Beat: Understanding and Mitigating Desynchronization Risks in Container IsolationZhi Li, Zhen Xu, Weijie Liu, XiaoFeng Wang et al.NDSS 2026
- CofferOS: Hardening OS-level Virtualization with RustMinkyu Jung, Chanshin Kwak, Junho Ahn, Sunho Park et al.EuroSys 2026
- BlackBox: A Container Security Monitor for Protecting Containers on Untrusted Operating SystemsAlexander Van't Hof, Jason NiehOSDI 2022 · 44 citations
- Harvesting Spare CPU Resources in Container SystemsAdam Hall, Anirudh Sarma, Esha Choukse, Umakishore Ramachandran et al.NSDI 2026 · 2 citations
