Cloud Native
Security Talks
RSS

KubeCon Europe 2018

Multi-Tenancy in Kubernetes: Best Practices Today, and Future Directions

David Oppenheimer, Google

Abstract

Kubernetes offers a set of features which, when used in the right combination and configured properly, enable secure multi-tenant clusters. But it’s not always obvious how to map particular multi-tenancy requirements to those features and configurations. As a result, people often resort to spinning up one cluster per user and/or workload, thereby foregoing the utilization and management benefits they could achieve by using a single shared cluster. This talk will describe a taxonomy of various multi-tenancy models that are possible on Kubenetes today, and how to configure the existing security/multi-tenancy features to satisfy each of those use cases. We will then describe some features that are on the horizon to provide even stronger, easier-to-use multi-tenancy in Kubernetes.

More from KubeCon Europe 2018

Open in the index →
  1. The Route To Rootless ContainersEd King, Pivotal & Julz Friedman, IBM 2018-05-02
  2. Securing your Kubernetes Delivery Pipelines with Notary and TUFLiam White & Michael Hough, IBM 2018-05-02
  3. Improving your Kubernetes Workload Security with Hardware VirtualizationFabian Deutsch, Red Hat & Samuel Ortiz, Intel 2018-05-02
  4. Establishing Image Provenance and Security in KubernetesAdrian Mouat, Container Solutions 2018-05-02
  5. Completely Securing the Software Supply Chain using Grafeas + in-totoLukas Puehringer, NYU & Wendy Dembowski, Google 2018-05-02
  6. No video Cloud Native Identity ManagementAndreas Zitzelsberger, QAware GmbH & Andrew Jessup, Scytale Inc. 2018-05-02
  7. OPA: The Cloud Native Policy EngineTorin Sandall, Styra 2018-05-03
  8. Good Enough for the Finance Industry: Achieving High Security at Scale with Microservices in KubernetesZachary Arnold & Austin Adams, Ygrene Energy Fund 2018-05-03
  9. Entitlements: Understandable Container Security ControlsJustin Cormack & Nassim Eddequiouaq, Docker 2018-05-03
  10. Container Isolation at Scale (Introducing gVisor)Dawn Chen & Zhengyu He, Google 2018-05-03
  11. Case Study: How Containers Makes Security and Compliance Instantly EasierJohn Morello, Twistlock 2018-05-03
  12. Applying Least Privileges through Kubernetes Admission ControllersBenjy Portnoy, Aqua Security 2018-05-03
  13. TL;DR NIST Container Security StandardsElsie Phillips, CoreOS 2018-05-04
  14. Secure PodsTim Allclair, Google 2018-05-04
  15. Kubernetes Runtime Security: What Happens if a Container Goes Bad?Jen Tong & Maya Kaczorowski, Google 2018-05-04
  16. From Kubelet to Istio: Kubernetes Network Security DemystifiedAndrew Martin, ControlPlane 2018-05-04
  17. A Hacker's Guide to Kubernetes and the CloudRory McCune, NCC Group PLC 2018-05-04