Kubernetes Security Best Practices - Ian Lewis, Google

  Переглядів 49,005

CNCF [Cloud Native Computing Foundation]

CNCF [Cloud Native Computing Foundation]

День тому

Don't miss KubeCon + CloudNativeCon 2020 events in Amsterdam March 30 - April 2, Shanghai July 28-30 and Boston November 17-20! Learn more at kubecon.io. The conference features presentations from developers and end users of Kubernetes, Prometheus, Envoy, and all of the other CNCF-hosted projects
Kubernetes Security Best Practices - Ian Lewis, Google
Containers give developers the ability to isolate applications from one another, but that’s not enough. Resource isolation is much different that security isolation. How do we make applications deployed in containers more secure? What tools can be we apply to our containers running in Kubernetes to make them more secure? How can we apply policy to our network and services to make sure applications only have access to what they need and nothing more?
In this talk, attendees will learn about the risks and attack surfaces of a Kubernetes cluster. s-We'll look at tools like PodSecurityPolicy, SELinux, AppArmor, seccomp, and sandboxed containers in action to improve the security of containers. We’ll then go up the stack and learn how to apply network policy to containers to further improve security.

КОМЕНТАРІ: 17
@domaincontroller
@domaincontroller 3 роки тому
07:33 Attacking Kubernetes cluster itself, Kubernetes API server 09:01 RBAC 10:58 API Firewall 11:35 NetworkPolicy 13:20 Get access to cluster components, etcd
@laprashant
@laprashant 2 роки тому
Thanks Ian, it's still relevant in 2021 😃
@venkatbollimuntha178
@venkatbollimuntha178 3 роки тому
Ian, Thanks so much. Great presentation, and excellent coverage of K8S security best practices.
@phanikumar1502
@phanikumar1502 3 роки тому
Hello Ian, Rocking presentation which is clear and easy to understand for newbies .
@rashmitrathod6873
@rashmitrathod6873 3 роки тому
Excellent presentation. Very concise in terms on identifying what are possible areas to secure and how to secure for containerized workload running on Kubernetes.
@roshelliwanag9447
@roshelliwanag9447 4 роки тому
Hi Ian. Your presentation is clear and I was able to grasp your ideas easily. Thanks. I am also interested in the remaining topics not covered in your presentation - Threat detection, Build Hygiene and SecOps. Could you recommend good articles or videos regarding those topics? Thanks in advance.
@tanelikantomaa9540
@tanelikantomaa9540 2 роки тому
Nice! Really good presentation with illustrative pictures. Thanks Ian!
@wilbertopalomar4187
@wilbertopalomar4187 2 роки тому
Thanks for the excellent presentation Ian. Great parallels on Defense In Depth principle where it underpins the logical flow: Network -> Host -> Supply Chain (Application) -> Data vs. a threat model driven by it (layered defense). Also, it's worth pondering on the importance of Infra Code security first (for those orgamisations mature enough to drive everything via code e.g. Terraform, Crossplane, or ClusterAPI) where it's critical on CI/CD/Progressive Delivery DevSecOps cycle given that it builds entirely on what's being presented.
@JavierPortillo1
@JavierPortillo1 3 роки тому
Thanks for your presentation
@chayanchoudhury6041
@chayanchoudhury6041 2 роки тому
Very helpful..precise..
@siavashmohammady9095
@siavashmohammady9095 2 роки тому
thank you so much
@udayprabhu4751
@udayprabhu4751 2 роки тому
Very good talk
@ChristianPeper
@ChristianPeper 10 місяців тому
👍thanks, even now
@CloudNativeJanitor
@CloudNativeJanitor 3 роки тому
awesome
@yongshengyang8144
@yongshengyang8144 3 роки тому
Nice topics
@nestorreveron
@nestorreveron 2 роки тому
Thanks
@nah0221
@nah0221 2 роки тому
fruitful !
Understanding the Cluster-API Structure Through the Openstack Provider - Jaesang Lee & Esther Kim
36:12
CNCF [Cloud Native Computing Foundation]
Переглядів 1,1 тис.
Hacking and Hardening Kubernetes Clusters by Example [I] - Brad Geesaman, Symantec
39:31
CNCF [Cloud Native Computing Foundation]
Переглядів 40 тис.
Що рятує українців від похмілля?😁 | #НовийКанал #ЄПитання
00:53
єПитання з Лесею Нікітюк
Переглядів 439 тис.
Vasiliy Lomachenko vs George Kambosos | INTERNATIONAL LIVE STREAM
3:10:05
Top Rank Boxing
Переглядів 1,1 млн
Tutorial: Communication Is Key - Understanding Kubernetes Networking - Jeff Poole, Vivint Smart Home
1:17:48
CNCF [Cloud Native Computing Foundation]
Переглядів 29 тис.
Internet Networks & Network Security | Google Cybersecurity Certificate
1:09:05
Google Career Certificates
Переглядів 119 тис.
Certifik8s: All You Need to Know About Certificates in Kubernetes [I] - Alexander Brand, Apprenda
35:57
CNCF [Cloud Native Computing Foundation]
Переглядів 43 тис.
Kubernetes Security Best Practices 2021 (From Container Specialist)
17:01
Cloud With Raj
Переглядів 14 тис.
Securing Kubernetes Secrets (Cloud Next '19)
42:27
Google Cloud Tech
Переглядів 19 тис.
Tutorial: Hands-on Hacking Kubernetes and Ways to Prevent It - Eric Smalling, Snyk
1:13:23
CNCF [Cloud Native Computing Foundation]
Переглядів 3 тис.
Securing Cluster Networking with Network Policies - Ahmet Balkan, Google
30:55
CNCF [Cloud Native Computing Foundation]
Переглядів 28 тис.
Do NOT Learn Kubernetes Without Knowing These Concepts...
13:01
Travis Media
Переглядів 202 тис.
Airpods’un Gizli Özelliği mi var?
0:14
Safak Novruz
Переглядів 2,4 млн
M4 iPad Pro Impressions: Well This is Awkward
12:51
Marques Brownlee
Переглядів 5 млн
Купите ЭТОТ БЮДЖЕТНИК вместо флагманов от Samsung, Xiaomi и Apple!
13:03
Thebox - о технике и гаджетах
Переглядів 22 тис.