BEGIN:VCALENDAR
VERSION:2.0
PRODID:Linklings LLC
BEGIN:VTIMEZONE
TZID:America/Chicago
X-LIC-LOCATION:America/Chicago
BEGIN:DAYLIGHT
TZOFFSETFROM:-0600
TZOFFSETTO:-0500
TZNAME:CDT
DTSTART:19700308T020000
RRULE:FREQ=YEARLY;BYMONTH=3;BYDAY=2SU
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:-0500
TZOFFSETTO:-0600
TZNAME:CST
DTSTART:19701101T020000
RRULE:FREQ=YEARLY;BYMONTH=11;BYDAY=1SU
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
DTSTAMP:20230124T171520Z
LOCATION:C140-142
DTSTART;TZID=America/Chicago:20221114T113000
DTEND;TZID=America/Chicago:20221114T120000
UID:submissions.supercomputing.org_SC22_sess438_ws_canopie112@linklings.co
 m
SUMMARY:A Separated Model for Running Rootless, Unprivileged PMIx-Enabled 
 HPC Applications in Kubernetes
DESCRIPTION:Workshop\n\nA Separated Model for Running Rootless, Unprivileg
 ed PMIx-Enabled HPC Applications in Kubernetes\n\nHursey\n\nHigh Performan
 ce Computing (HPC) applications must be containerized to run in a Kubernet
 es (K8s) environment. The traditional model for running HPC applications i
 n a K8s environment requires the Application Container (APP) to include th
 e runtime environment and the launch support mechanisms, in addition to th
 e application. This requirement can increase the APP size and introduce se
 curity vulnerabilities. The separated model presented detaches the runtime
  from the APP. This allows the system administrators to define, maintain, 
 and secure the Runtime Environment Container (REC). A PMIx library connect
 s the APP and REC. The PMIx library serves as a runtime communication cond
 uit for HPC parallel libraries (like MPI) to perform necessary functions l
 ike inter-process wire-up. The APP is nested within the REC using unprivil
 eged, rootless Podman. The separated model is demonstrated by running a se
 t of HPC applications in an off-the-shelf K8s system.\n\nSession Format: R
 ecorded\n\nRegistration Category: Workshop Reg Pass
END:VEVENT
END:VCALENDAR
