Cloud Native
Security Talks
RSS

KubeCon Europe 2022

Throw Away Your Passwords: Trusting Workload Identity

Ric Featherstone, ControlPlane

Abstract

Trust is required to secure our systems: we need it to bootstrap infrastructure, to run workloads, and to reassure our customers of their privacy. But how do we establish and secure this “trust” in a dynamic cloud native system?Historically we relied upon identifiers such as IP addresses, passwords, and certificates, but can we do better than these antiquated authentication mechanisms? In this talk we:Demystify machine identity and its relationship to secrets management and access controlDiscuss the issues with historical approaches in a cloud native environmentSolve the “bottom turtle” trust bootstrap quandaryAppraise the open source implementations and technologies available to youDemonstrate practical examples of how to acquire a workload identity or secret zeroStrive for a world in which passwords and static keys are replaced by dynamic credentials and hardware roots of trustClick here to view captioning/translation in the MeetingPlay platform!

More from KubeCon Europe 2022

Open in the index →
  1. Lightning Talk: Secure Multi User HPC Jobs in Kubernetes with KyvernoTrey Dockendorf, Ohio Supercomputer Center 2022-05-17
  2. Trampoline Pods: Node to Admin PrivEsc Built Into Popular K8s PlatformsYuval Avrahami & Shaul Ben Hai, Palo Alto Networks 2022-05-18
  3. The Hitchhiker's Guide to Pod SecurityLachlan Evenson, Microsoft 2022-05-18
  4. Securing Kubernetes Applications by Crafting Custom Seccomp ProfilesSascha Grunert, Red Hat 2022-05-18
  5. K8s and Active Directory Can Be Friends! How to Use Dex to Bridge the GapOnkar Bhat, Kasten by Veeam 2022-05-18
  6. How Attackers Use Exposed Prometheus Server to Exploit Kubernetes ClustersDavid de Torres Huerta & Miguel Hernández, Sysdig 2022-05-18
  7. Bypassing Falco: How to Compromise a Cluster without Tripping the SOCShay Berkovich, BlackBerry 2022-05-18
  8. Threat Modelling Kubernetes: A Lightspeed IntroductionLewis Denham-Parry, Control Plane 2022-05-19
  9. Securing Your Container Native Supply Chain with SLSA, Github and TektonLaurent Simon, Google & Priya Wadhwa, Chainguard 2022-05-19
  10. Make the Secure Kubernetes Supply Chain Work for YouAdolfo García Veytia, Chainguard 2022-05-19
  11. Fun with Continuous ComplianceAnn Wallace, Shopify & Zeal Somani, Google 2022-05-19
  12. Distributing Supply Chain Artifacts with OCI & ORAS ArtifactsSteve Lasker, Microsoft 2022-05-19
  13. Too Much to Choose – Making Sense of a Smorgasbord of Security StandardsAnais Urlichs & Rory McCune, Aqua Security 2022-05-20
  14. Three Surprising K8s Networking “Features” and How to Defend Against ThemJames Cleverley-Prance, ControlPlane 2022-05-20
  15. Multi-Cloud Workload Identity With SPIFFEJake Sanders & Charlie Egan, Jetstack 2022-05-20
  16. Full Mesh Encryption in Kubernetes with WireGuard and CalicoPeter Kelly, Tigera 2022-05-20
  17. Attacking & Defending Kubernetes TEE Enclaves in Critical InfrastructureRobert Ficcaglia, SunStone Secure, LLC 2022-05-20