Cloud Native
Security Talks
RSS

KubeCon Europe 2025

Container Runtimes... on Lockdown: The Hidden Costs of Multi-tenant Workloads

Lewis Denham-Parry, Edera & Caleb Woodbine, ii.nz

Abstract

Container runtimes form the bedrock of Kubernetes, but running diverse workloads side-by-side introduces complex security challenges that many teams overlook. This talk peels back the layers of container isolation, starting with the fundamentals of how containers operate as Linux processes and evolving through today’s runtime landscape.We’ll dive deep into the hidden costs and security implications of different container runtime choices in multi-tenant environments. Through real-world examples and performance benchmarks, we’ll explore the delicate balance between isolation and efficiency. You’ll learn about emerging solutions in the container runtime space and practical approaches to securing workloads without sacrificing performance.Attendees will leave with critical security considerations for choosing container runtimes, strategies for workload isolation, and tools to evaluate isolation versus performance tradeoffs.

More from KubeCon Europe 2025

Open in the index →
  1. Trust No One: Secure Storage With Confidential ContainersAurélien Bombo, Microsoft 2025-04-02
  2. Signed, Sealed, Delivered - Sign and Verify All the ThingsJeremy Rickard, Microsoft 2025-04-02
  3. Securing AI Workloads: Building Zero-Trust Architecture for LLM ApplicationsRohit Ghumare, Taikun & Joinal Ahmed, NTG 2025-04-02
  4. Weaving a VEX Feed Through the Kubernetes ProjectAdolfo García Veytia, Stacklok 2025-04-03
  5. Redefining Access Control: Scaling Policy as Code for Humans and AI AgentsRaz Cohen, Permit.io 2025-04-03
  6. Open Source Malware or a Vulnerability? The Philosophical Debate and How To MitigateBrian Fox, Sonatype; Madelein van der Hout, Forrester Research Inc.; Santiago Torres-Arias, Purdue University 2025-04-03
  7. Mind the Gap: Bridging Supply Chain Policy With Git-less GitOps and GUACMichael Lieberman, Kusari & Andrew Martin, ControlPlane 2025-04-03
  8. Identity-based Trust - Till Death Do We Part?John Kjell, ControlPlane & Kairo De Araujo, Independent 2025-04-03
  9. IAM, Agent: Identity for Autonomous AIMatthew Bates, Cofide 2025-04-03
  10. ​​SPIFFE in Practice: Universal Identity for WebAssembly WorkloadsJoonas Bergius, Cosmonic & Colin Murphy, Adobe 2025-04-03
  11. Zero Trust at Shopify Scale: Automating MTLS Across Thousands of ServicesDani Santos & Michelle Mali, Shopify 2025-04-04
  12. Why Don’t We Have Both? Track Build- and Run-time Information for Security With Kubescape and GUACJeff Mendoza, Kusari & Ben Hirschberg, ARMO 2025-04-04
  13. From Chaos To Control: Migrating Access Control To OpenFGA in a Multi-Tenant WorldJo Guerreiro, Grafana Labs & Poovamraj Thanganadar Thiagarajan, Okta 2025-04-04
  14. Fresh Secrets From the Docks: Lessons Learnt From Analyzing 180,000 Public DockerHub ImagesGuillaume Valadon, GitGuardian 2025-04-04
  15. Enhancing Software Composition Analysis Resilience Against Container Image ObfuscationAgathe Blaise, Thales & Jacopo Bufalino, CNAM 2025-04-04
  16. EVAPorating Kubernetes Security Risk: Adopting Validating Admission Policy at ScaleKaitlyn Lee & Jordan Conard, Datadog 2025-04-04
  17. Do Your Containers Even Lift – A Hardening Guide for K8s ContainersCailyn Edwards & Daniel Murphy, Okta 2025-04-04
  18. Compliance at the Speed of Innovation: Leveraging AI-Driven Automation for Real-Time Regulatory ReadLarry Carvalho, RobustCloud LLC; Simon Metson, EnterpriseDB; Robert Ficcaglia, Sunstone Secure, LLC; Anca Sailer, Red Hat / IBM; Yuji Watanabe, IBM Japa 2025-04-04