Nspawn.org is a Docker-like container platform that uses systemd-nspawn to manage OCI images from multiple registries, storing shared layers and exposing machines as standard systemd units. It provides a unified interface for pulling, building, and running containers with networking, volume management, and polkit-based access control, written as a single Rust binary.
Fedora Atomic Desktop sealed bootable container images are now available for testing. These images include a complete verified boot chain with Secure Boot support, featuring systemd-boot, a Unified Kernel Image, and composefs with fs-verity. The implementation enables passwordless TPM-based disk unlocking while maintaining security.
Systemd v262 addresses TPM PCR scarcity by introducing NvPCRs—additional PCR-like registers in TPM non-volatile memory—with a reworked anchoring design that improves security. The article explains why PCRs are limited, how NvPCRs solve the problem, and provides a hands-on guide to building NvPCRs against a software TPM.