Cloud Native
Security Talks
RSS

KubeCon Europe 2023

Zero Privilege Architectures

Thijs Ebbers & Diana Iordan, ING

Abstract

In this talk we’ll start out with a bit of Dutch folkore (Hey, we’re in Amsterdam :-)), we’ll explain what is wrong with typical “Least Privilege” & “Zero Trust” implementations and ask the confronting question: “Are we playing for a Draw or are we playing to Win against our IT security adversaries…? Next we’ll use some “classical” laws of war/diplomacy, biology/business and engineering to develop a modern IT architecture suitable for todays challenges. This architecture is based on desired state infrastructure, built using CI/CD and Infra/Policy-as-code. It stores its data in Data Services. It uses Events, Observability and IAM to operate securely. (In summary: we cover quite a lot of the CNCF landscape…) We’ll explain this architecture and show different views of this architecture for: - Architects/Developers/Engineers - C-level Managers - CISO/Auditors And answer some questions like: - Can it be build ? (spoiler : Yes, ING is running it today, details in previous talks we gave at OpenShift Commons Detroit & San Diego) - My workloads won’t fit - We’re not a bank, we cannot afford this - Doesn’t this collide with current views/implementations of established entities in the security(/compliancy) industry ? To conclude answer any other question the audience asks

More from KubeCon Europe 2023

Open in the index →
  1. Using OpenTelemetry for Application Security, with a Real Life ExampleRon Vider, Oxeye 2023-04-19
  2. The Hacker's Guide to KubernetesPatrycja Wegrzynowicz, Form3 2023-04-19
  3. From SBOMs to IBOMs - Know What's Happening in Your ClustersIdo Neeman, Firefly 2023-04-19
  4. Confidential Containers Made EasyFabiano Fidencio, Intel & Jens Freimann, Red Hat 2023-04-19
  5. Cert-Manager Can Do SPIFFE? Solving Multi-Cloud Workload Identity Using a De Facto Standard ToolThomas Meadows, Jetstack & Joshua Van Leeuwen, Diagrid 2023-04-19
  6. Anatomy of a Cloud Security Breach - 7 Deadly SinsMaya Levine, Sysdig 2023-04-19
  7. Adopting Network Policies in Highly Secure EnvironmentsRaymond de Jong, Isovalent 2023-04-19
  8. A Confidential Story of Well-Kept SecretsLukonde Mwila, AWS 2023-04-19
  9. 🦝 RBAC to the Future: Untangling Authorization in KubernetesJimmy Mesta, KSOC 2023-04-19
  10. 🦝 Canals and Bridges: Using Amsterdam’s Transit System To Secure K8s NetworksCailyn Edwards, Shopify 2023-04-19
  11. Running Not Root Made EasyLuboslav Pivarc, Red Hat 2023-04-20
  12. Rotate Roots Right Round: Using Cert-Manager for Safer Private PKIAshley Davis, Jetstack 2023-04-20
  13. Mind the Gap! Bringing Together Cloud Services and Managed K8s EnvironmentsChristophe Tafani-Dereeper, Datadog & Diego Comas, Sourcegraph 2023-04-20
  14. Kubernetes Defensive Monitoring with PrometheusDavid de Torres Huerta & Mirco De Zorzi, Sysdig 2023-04-20
  15. Improve Vulnerability Management with OCI Artifacts – It Is That Easy!Itay Shakury, Aqua Security & Toddy Mladenov , Microsoft 2023-04-20
  16. Image Signing and Runtime Verification at Scale: Datadog's JourneyEthan Lowman, Datadog 2023-04-20
  17. Cluster Grey Zone: Risks in Managed Cluster MiddlewareShay Berkovich & Barak Sharoni, Wiz 2023-04-20
  18. Checking the Chains at the Gate: Building Supply Chain Policies with Gatekeeper and RatifyJeremy Rickard, Microsoft 2023-04-20
  19. Back to the Future: Next-Generation Cloud Native SecurityMatt Jarvis, Snyk & Andrew Martin, Control Plane 2023-04-20
  20. Automated Cloud-Native Incident Response with Kubernetes and Service MeshMatt Turner, Tetrate & Francesco Beltramini, Control Plane 2023-04-20
  21. No video 🦝 Minimalism: Key to Cloud SecurityBarun Acharya, Accuknox 2023-04-20
  22. 🦝 Interactive Playground to Learn Kubernetes and Cloud Native SecurityMadhu Akula 2023-04-20
  23. 🦝 Guardians of the Runtime: Leveraging Behavioral Analysis and PoliciesBen Hirschberg, ARMO 2023-04-20
  24. What Can Go Wrong When You Trust Nobody? Threat Modeling Zero TrustJames Callaghan & Richard Featherstone, ControlPlane 2023-04-21
  25. The Next Log4jshell?! Preparing for CVEs with eBPF!Natalia Reka Ivanko & John Fastabend, Isovalent 2023-04-21
  26. Prevent Embarrassing Cluster Takeovers with This One Simple Trick!Daniele de Araujo dos Santos & Shane Lawrence, Shopify 2023-04-21
  27. Practical Challenges with Pod Security AdmissionV Körbes & Christian Schlotter, VMware 2023-04-21
  28. Malicious Compliance: Reflections on Trusting Container ScannersIan Coldwater, Independent; Duffie Cooley, Isovalent; Brad Geesaman, Ghost Security; Rory McCune, Datadog 2023-04-21
  29. Least Privilege Containers: Keeping a Bad Day from Getting WorseGreg Castle & Vinayak Goyal, Google 2023-04-21
  30. Can You Keep a Secret? on Secret Management in KubernetesLiav Yona & Gal Cohen, Firefly 2023-04-21
  31. Building SLSA 3 Conforment Attestors for Artifacts Generated on GitHubIan Lewis & Asra Ali, Google 2023-04-21
  32. A Look Under the Hood of CNCF Security AuditsAdam Korczynski & David Korczynski, Ada Logics 2023-04-21
  33. 🦝 The Top 10 List of Istio Security Risks and Mitigation StrategiesJosé Carlos Chávez, Tetrate 2023-04-21
  34. 🦝 Secure the Build, Secure the Cloud: Using OIDC Tokens in CI/CD PipelinesAlex Ilgayev & Elad Pticha, Cycode 2023-04-21