Cloud Native
Security Talks
RSS

KubeCon Europe 2019

Securing Kubernetes with Trusted Platform Module (TPM)

Alex Tcherniakhovski & Andrew Lytvynov, Google

Abstract

TPM is a discrete tamper-resistant device soldered to the motherboard and it operates independently of its host. TPM devices are designed to protect sensitive credentials at the hardware level: credentials created and stored within TPM devices cannot be extracted, even if host is compromised. Additionally, TPM devices provide a suite of cryptographic operations for applications to leverage. In this demo heavy session, we will review core TPM capabilities and how they could be used in for extending Kubernetes security. Attendees will leave with understanding how to utilize TPM in the context of Kubernetes. Concretely, the following scenarios will be covered: - Bootstrap trusted identity of cluster nodes - Seal sensitive data - Generate cryptographically protected logs - Generate unexportable TLS credentials

More from KubeCon Europe 2019

Open in the index →
  1. Using eBPF to Bring Kubernetes-Aware Security to the Linux KernelDan Wendlandt, Isovalent 2019-05-21
  2. Portable, Universal Single Sign-On for Your ClustersMiguel Martinez, Bitnami 2019-05-21
  3. Kubernetes + Encrypted Memory = Security * PrivacyHarshal Patil & Pradipta Banerjee, IBM 2019-05-21
  4. Fine-Grained Permissions in Kubernetes: What’s Missing, and How to Fix ThatVallery Lancey, Lyft & Seth McCombs, Triller 2019-05-21
  5. Envoy SDS: Fortifying Istio SecurityYonggang Liu & Quanjie Lin, Google 2019-05-21
  6. Zero Trust Service Mesh with Calico, SPIRE, and EnvoyShaun Crampton, Tigera & Evan Gilman, Scytale 2019-05-22
  7. Smarter Kubernetes Access Control: A Simpler Approach to AuthRob Scott, ReactiveOps 2019-05-22
  8. Inside the CNCF Project Security ReviewsJustin Cormack, Docker 2019-05-22
  9. Crafty Requests: Deep Dive Into Kubernetes CVE-2018-1002105Ian Coldwater, Heroku 2019-05-22
  10. Container Forensics: What to Do When Your Cluster is a ClusterMaya Kaczorowski & Ann Wallace, Google 2019-05-22
  11. Caller ID in KubernetesMichael Danese, Google 2019-05-22
  12. Uber x Security: Why and How We Built Our Workload Identity PlatformTyler Julian, Uber & Daniel Feldman, Scytale 2019-05-23
  13. Securing Multi-Cloud Cross-Cluster Communication with SPIFFE and SPIREEvan Gilman, Scytale, Inc. 2019-05-23
  14. Secrets Store CSI Driver-Bring Your Own Enterprise Secrets Store to K8sRita Zhang, Microsoft & Anubhav Mishra, HashiCorp 2019-05-23
  15. Protecting the Data LakeAsh Narkar, Styra, Inc 2019-05-23
  16. DIY Pen-Testing for Your Kubernetes ClusterLiz Rice, Aqua Security 2019-05-23