Cloud Native
Security Talks
RSS

KubeCon North America 2022

Tutorial: Reducing the Sticker Price Of Kubernetes Security

Pushkar Joglekar, VMware

Abstract

NOTE: To have the best experience during the tutorial, please download the tools in this section of the README: https://github.com/PushkarJ/kccncna-22-tutorial#pre-requisites prior to the session. Further Reading is on Slide 52 of the attached slide deck PDF. “Securing Kubernetes is full of landmines with Dragons lurking everywhere you see yaml.” Sounds familiar? This statement captures the general feeling of many years of many End User admins who are tasked with managing Kubernetes clusters. In the last couple of years, however, the community has worked on several incremental changes that have improved the security posture of Kubernetes significantly. Good news is that they are simple and do not require weeks to get them right! In this tutorial, Pushkar Joglekar will take you on a journey of learning hands-on techniques, open source tools, and newer security enhancements that will make deploying a secure kubernetes cluster faster and a little bit easier. We will start with verifying signed kubernetes release images for any version of your choice, applying Pod Security Standards at cluster or namespace level and configuring Runtime SecComp Profile by default for all workloads in a cluster running on your own system. At the end we will tie all these security features to real world vulnerabilities and known attacks to get that fuzzy and warm feeling, on a cold October day in Detroit, of being able to prevent vulnerability exploits in your clusters because you applied what you learnt in this tutorial. Happy Honking Defensively !!!

More from KubeCon North America 2022

Open in the index →
  1. Using the EBPF Superpowers To Generate Kubernetes Security PoliciesMauricio Vásquez Bernal & Alban Crequy, Microsoft 2022-10-26
  2. Untrusted Execution: Attacking the Cloud Native Supply ChainAndrew Martin, ControlPlane 2022-10-26
  3. Securing the IaC Supply ChainJesse Sanford, Autodesk & Jason Hall, Chainguard 2022-10-26
  4. SLSA FRSCA Recipe For Secure Supply ChainParth Patel & Michael Lieberman, Kusari 2022-10-26
  5. SBOM X-Ray Superpowers: Making Better SBOMs, Using SBOMsBrandon Lum, Google & Chris Phillips, Anchore 2022-10-26
  6. Kubernetes to Cloud Attack Vectors: Demos InsideDanny Hershko Shemesh & Alon Schindel, Wiz 2022-10-26
  7. Armoring Cloud Native Workloads With LSM SuperpowersBarun Acharya, Accuknox 2022-10-26
  8. Securing Edge Workloads With Cert-Manager And SPIFFESitaram IYER & Riaz Mohamed, Jetstack Ltd 2022-10-27
  9. Run As “Root”, Not Root: User Namespaces In K8sMarga Manterola, Isovalent & Rodrigo Campos Catelin, Microsoft 2022-10-27
  10. Path To Production: Sustainable Compliance In Strict EnvironmentsChip Zoller, Nirmata & Brandt Keller, Defense Unicorns 2022-10-27
  11. Migrating From PodSecurityPolicyTim Allclair & Sam Stoelinga, Google 2022-10-27
  12. It's Dangerous To SLSA Alone Out There! Take This Artifact Knowledge Graph!Mihai Maruseac, Google & Michael Lieberman, Independent 2022-10-27
  13. How the Argo Project Transitioned From Security Aware To Security FirstHenrik Blixt & Michael Crenshaw, Intuit 2022-10-27
  14. Hack Back; Let’s Learn Security With CTFs!Lewis Denham-Parry, Chainguard & Natalia Reka Ivanko, Isovalent 2022-10-27
  15. You Like It Or Not; You Need It! - PKI And Certificate ManagementShweta Vohra, IBM 2022-10-28
  16. What Data Tells Us About Software Supply Chain Security & What To Do About ItJosh Bressers, Anchore; Tracy Miranda, Chainguard; John Yeoh, Cloud Security Alliance; Eric Tice, Wipro 2022-10-28
  17. The Insider Threat: Third-Party Applications In Your ClusterDagan Henderson, Raft, LLC & Will Kline, Dark Wolf Solutions 2022-10-28
  18. So, SBOMs Matter…Now What?Sophie Wigmore & Frankie Gallina-Jones, VMware 2022-10-28
  19. Putting Hackers Breaching Your Cluster In Automatic QuarantineZiv Nevo, IBM 2022-10-28
  20. Fuzzing Session: Finding Bugs and Vulnerabilities AutomaticallyDavid Korczynski & Adam Korczynski, Ada Logics 2022-10-28
  21. B’Envoy-age to Pre-Quantum EncryptionDaniel Rouhana, Independent; Emma Dickenson, Washington State University; Doron Podoleanu, F5 2022-10-28