2026-06-16 –, Sapphire
Compliance doesn't have to mean installing a black-box proprietary agent. For organisations running Fedora, "Freedom" means the ability to audit your own security tools. But as the Enterprise Linux world shifts toward immutable, image-based systems Silverblue, Kinoite, and RHEL's bootc. the rules are changing.
This session bridges the gap between today's compliance requirements and tomorrow's atomic desktops. We'll start by demonstrating how Fleet translates NIST controls into transparent SQL queries on traditional Fedora workstations. Then we'll explore what breaks when the filesystem goes read-only, and how to adapt.
We will cover:
Compliance as Code: Mapping NIST 800-53/171 controls to osquery policies
The Immutable Challenge: Why traditional remediation fails on atomic systems
Querying the Image: Inspecting rpm-ostree status, verifying boot digests, and detecting drift
Practical Patterns: Real-world deployment considerations (like where Fleet's writable state actually lives)
Join us to see how open-source observability is evolving alongside the Cloud Native Desktop.