Cloud Native
Security Talks
RSS

KubeCon North America 2023

K8s Auth{N,Z} at Robinhood - Learning from Reductions, Migrations and Designing Automation

Sujith Katakam & Karen Tu, Robinhood Markets, Inc.

Abstract

Kubernetes RBAC seems simple enough - specify the resource that you need access to and bind it to who needs it - what’s the problem? In the quest of implementing least privilege company-wide, we ran into seemingly simple but practically complicated questions, for example: How do we figure out who needs what, for how long? How do we grant access in a timely and time-bound manner? How do we think about what permissions need what level of scrutiny? How do we clean up existing permissions and migrate to a different Identity Provider and authentication mechanism with as minimal user friction as possible? Work is still ongoing to clean up existing problematic permissions as well as design a sustainable solution going forward. Join us in this talk where we share the challenges and learnings we have on managing authentication and authorization at Robinhood. We’ll also include a “fun” story of how our OIDC client got deleted!

More from KubeCon North America 2023

Open in the index →
  1. Wolfi: Intro to the Linux Undistro Helping Build Small, up-to-Date, CVE Free Cloud ImagesJames Rawlings, Chainguard 2023-11-07
  2. The Attacker Perspective - Insights From Hacking Alibaba Cloud's Managed K8s EnvironmentsHillai Ben-Sasson & Ronen Shustin, Wiz 2023-11-07
  3. Securing Kubernetes: Migrating from Long-Lived to Time-Bound Tokens Without Disrupting Existing AppsYuan Chen & James Munnelly, Apple Inc. 2023-11-07
  4. Cloud Native Application Threat Modeling and Adversary Emulation : Techniques and ToolsRafik Harabi, Sysdig 2023-11-07
  5. No video Clean up on Aisle Cloud!Sara Johnson, Boeing 2023-11-07
  6. Challenge to Implementing “Scalable” Authorization with KeycloakYoshiyuki Tabata, Hitachi, Ltd. 2023-11-07
  7. Arbitrary Code & File Execution in R/O FS – Am I Write?Golan Myers, WithSecure 2023-11-07
  8. All Cloud-Native Services Are Vulnerable — Block Exploits with Security Behavior AnalyticsDavid Hadas, IBM Research & Roland Huß, Red Hat 2023-11-07
  9. A Wind of Change for Threat DetectionMelissa Kilby, Apple 2023-11-07
  10. The Next Frontier: Exploring the Confidentiality of Kubernetes Control PlanesJens Freimann, Red Hat 2023-11-08
  11. Securing Identity and Authorization in MicroservicesAtul Tulshibagwale, SGNL 2023-11-08
  12. Paint the Picture! - Detecting Suspicious Data Patterns in Encrypted Traffic with eBPF and KTLSNatalia Reka Ivanko & John Fastabend, Isovalent 2023-11-08
  13. Identity-Based Segmentation: An Emerging Standard for Zero Trust from NISTZack Butcher, Tetrate 2023-11-08
  14. Grifts Ahoy! Bracing for the AI TideShane Lawrence, Shopify 2023-11-08
  15. Forget Everything You Know About Image Vulnerability and PrioritizationBen Hirschberg, ARMO 2023-11-08
  16. Five Years of Cloud Native RustAlex Leong, Buoyant 2023-11-08
  17. Eraser: Cleaning up Vulnerable Images from Kubernetes NodesPeter Engelbert & Ashna Mehrotra, Microsoft 2023-11-08
  18. Supercharge Your Software Supply Chain Security Strategy with Multi-SBOM IntegrationPallavi Kalapatapu, Cisco 2023-11-09
  19. Safeguarding Clusters: Exploring the Benefits and Navigating the Dangers of Admission ControllersAmine Hilaly & Igor Velichkovich, AWS 2023-11-09
  20. RBACdoors: How Cryptominers Are Exploiting RBAC MisconfigsGreg Castle & Vinayak Goyal, Google 2023-11-09
  21. OIDC and Workload Identity in KubernetesAshutosh Kumar, Elastic & Anish Ramasekar, Microsoft 2023-11-09
  22. K8s Post-Exploitation: Privilege Escalation, Sidecar Container Injection, and Runtime SecurityMagno Logan, GoHacking 2023-11-09