Description: HPC environments are shared, multi-tenant systems where hundreds of users run jobs side by side on the same physical infrastructure. This creates a unique security landscape: the cluster administrators must isolate users from each other and from the underlying system, while users themselves are responsible for protecting their data, credentials, and workloads as they move through the pipeline. This workshop walks through HPC security end to end: what the infrastructure team does to keep the cluster safe, what you as a user can (and should) do to protect your own work, and how to secure the containers you bring onto the system.
Scope and Topics:
Part 1 - Infrastructure Security (13:00 - 13:30)
How the HPC platform itself is hardened, largely invisible to the end user but foundational to everything else: process and resource isolation, storage isolation, network security, IAM, auditing, scheduler-level security, etc.
Part 2 — What You Can Do as a User (13:40 - 14:10)
Best practices, Slurm and system features users control to protect their own jobs and data, such as exclusive mode, secure data transfers and data management, encryption, revoking sessions and keys, cleaning the data from the compute node, etc.
Part 3 - Container Security (14:20 - 14:50)
Because containers are the primary way users package and run software on HPC, they deserve their own layer of scrutiny: image signing, signature verification, vulnerability scanning, SBOMs, dealing with sensitive data, registries and other security controls.
Difficulty: Beginner - Intermediate
Language: English
Date and time: 08. 10. 2026 at 13.00
Max. number of participants: 30
Virtual location: ZOOM
Prerequisite knowledge: Having a basic knowledge of Linux is expected. Users should already have basic understanding of HPC systems.
Target audience: Industry, Academia, Public sector
After the workshop, participants will understand:
• The shared responsibility model between HPC infrastructure teams and end users when it comes to security.
• The mechanisms HPC centres use to isolate users, jobs, and data from one another at the OS, network, and scheduler level.
• The practical steps users should take to protect their own data and workloads while working on a shared system.
• How to secure the full lifecycle of a container, from build to signing, to scanning, to runtime, before and while using it on HPC.
Organiser:

Lecturers:
| Ime: | Barbara Krašovec |
| Opis: | Barbara Krašovec is an HPC systems architect at the Jožef Stefan Institute in Slovenia. She has over 15 years’ experience in HPC, cloud and distributed systems, virtualisation, and cybersecurity. She is a member of SLING, Slovenia’s national supercomputing network, EuroHPC Vega design and administration teams. She also serves on the EGI CSIRT and the EOSC EU Node security team, where she supports the security of European research infrastructure. Her work spans architecture, deployment, and operations of advanced computing environments, with a strong focus on secure, scalable solutions for scientific and industrial applications. |
| E-mail: | info@sling.si |
| Ime: | Dejan Lesjak |
| Opis: | Systems architect at Jozef Stefan Institute. |
| E-naslov: | info@sling.si |

Projekt EuroCC 3 je prejel sredstva Skupnega podjetja za evropsko visokozmogljivo računalništvo (EuroHPC JU) na podlagi Sporazuma o dodelitvi sredstev št. 101306701. Skupno podjetje EuroHPC prejema podporo programa Evropske unije Digitalna Evropa ter naslednjih držav: Nemčije, Albanije, Avstrije, Belgije, Bosne in Hercegovine, Bolgarije, Hrvaške, Cipra, Češke, Danske, Estonije, Finske, Francije, Grčije, Madžarske, Islandije, Irske, Italije, Latvije, Litve, Luksemburga, Malte, Črne gore, Nizozemske, Severne Makedonije, Norveške, Poljske, Portugalske, Romunije, Srbije, Slovaške, Slovenije, Španije, Švedske, Turčije in Kosova.
Financira Evropska unija. Izražena stališča in mnenja so izključno stališča avtorjev ter ne odražajo nujno stališč Evropske unije ali Skupnega podjetja EuroHPC. Zanje ne moreta biti odgovorna niti Evropska unija niti Skupno podjetje EuroHPC.
Nacionalni kompetenčni center SLING sofinancira Ministrstvo za izobraževanje, znanost in mladino Republike Slovenije.
HPC in Europe je krovna znamka, ki združuje evropske pobude na področju visokozmogljivega računalništva v več kot 36 državah.

