Cloud Native
Security Talks
RSS

KubeCon North America 2023

Eraser: Cleaning up Vulnerable Images from Kubernetes Nodes

Peter Engelbert & Ashna Mehrotra, Microsoft

Abstract

Supply chain security is an increasingly important issue in cloud-native computing: the number of attacks has grown by over 300% since 2021. It is common for pipelines to build and push images to the cluster, but uncommon for those images to be removed from a node’s local store once a CVE has been disclosed. Kubernetes has no built-in solution to this problem: its garbage collection only responds to disk pressure. As images become outdated, they present a risk as users may run a vulnerable container. Eraser, a CNCF sandbox project, is an open source solution that automates the scanning and removal of images. What distinguishes Eraser is that it gives more control over removal: the developer decides what gets removed and when. By default, Eraser uses Trivy to scan images based on a given threshold of vulnerability. Images can also be removed based on custom logic. The talk will begin with a demo of Eraser in action, before showing an example of customizing the removal process.

More from KubeCon North America 2023

Open in the index →
  1. Wolfi: Intro to the Linux Undistro Helping Build Small, up-to-Date, CVE Free Cloud ImagesJames Rawlings, Chainguard 2023-11-07
  2. The Attacker Perspective - Insights From Hacking Alibaba Cloud's Managed K8s EnvironmentsHillai Ben-Sasson & Ronen Shustin, Wiz 2023-11-07
  3. Securing Kubernetes: Migrating from Long-Lived to Time-Bound Tokens Without Disrupting Existing AppsYuan Chen & James Munnelly, Apple Inc. 2023-11-07
  4. Cloud Native Application Threat Modeling and Adversary Emulation : Techniques and ToolsRafik Harabi, Sysdig 2023-11-07
  5. No video Clean up on Aisle Cloud!Sara Johnson, Boeing 2023-11-07
  6. Challenge to Implementing “Scalable” Authorization with KeycloakYoshiyuki Tabata, Hitachi, Ltd. 2023-11-07
  7. Arbitrary Code & File Execution in R/O FS – Am I Write?Golan Myers, WithSecure 2023-11-07
  8. All Cloud-Native Services Are Vulnerable — Block Exploits with Security Behavior AnalyticsDavid Hadas, IBM Research & Roland Huß, Red Hat 2023-11-07
  9. A Wind of Change for Threat DetectionMelissa Kilby, Apple 2023-11-07
  10. The Next Frontier: Exploring the Confidentiality of Kubernetes Control PlanesJens Freimann, Red Hat 2023-11-08
  11. Securing Identity and Authorization in MicroservicesAtul Tulshibagwale, SGNL 2023-11-08
  12. Paint the Picture! - Detecting Suspicious Data Patterns in Encrypted Traffic with eBPF and KTLSNatalia Reka Ivanko & John Fastabend, Isovalent 2023-11-08
  13. K8s Auth{N,Z} at Robinhood - Learning from Reductions, Migrations and Designing AutomationSujith Katakam & Karen Tu, Robinhood Markets, Inc. 2023-11-08
  14. Identity-Based Segmentation: An Emerging Standard for Zero Trust from NISTZack Butcher, Tetrate 2023-11-08
  15. Grifts Ahoy! Bracing for the AI TideShane Lawrence, Shopify 2023-11-08
  16. Forget Everything You Know About Image Vulnerability and PrioritizationBen Hirschberg, ARMO 2023-11-08
  17. Five Years of Cloud Native RustAlex Leong, Buoyant 2023-11-08
  18. Supercharge Your Software Supply Chain Security Strategy with Multi-SBOM IntegrationPallavi Kalapatapu, Cisco 2023-11-09
  19. Safeguarding Clusters: Exploring the Benefits and Navigating the Dangers of Admission ControllersAmine Hilaly & Igor Velichkovich, AWS 2023-11-09
  20. RBACdoors: How Cryptominers Are Exploiting RBAC MisconfigsGreg Castle & Vinayak Goyal, Google 2023-11-09
  21. OIDC and Workload Identity in KubernetesAshutosh Kumar, Elastic & Anish Ramasekar, Microsoft 2023-11-09
  22. K8s Post-Exploitation: Privilege Escalation, Sidecar Container Injection, and Runtime SecurityMagno Logan, GoHacking 2023-11-09