Cloud Native
Security Talks
RSS

KubeCon North America 2019

The Devil in the Details: Kubernetes’ First Security Assessment

Aaron Small, Google & Jay Beale, InGuardians

Abstract

In October of last year, the Kubernetes project created a new Security Audit working group and began Kubernetes’ first comprehensive third-party security assessment. In the months that followed, we worked closely with Trail of Bits and Atredis Partners to assess and improve Kubernetes’ security posture.  Through code review and penetration testing, we found and addressed 37 new vulnerabilities.  With support from many Kubernetes contributors, the third party security firms and Kubernetes project produced a formal threat model covering eight critical components across six different trust zones.  In this talk, we will share our findings, methodology, and vision for future security investments.  We’ll discuss what the work uncovered, and what this means to Kubernetes security both now and for the future.

More from KubeCon North America 2019

Open in the index →
  1. Walls Within Walls: What if Your Attacker Knows Parkour?Tim Allclair & Greg Castle, Google 2019-11-19
  2. Panel: Control Plane vs Data Plane: Untangling the Tenets of MultitenancyTasha Drew, VMware; Sanjeev Rampal, Cisco; Ryan Bezdicek, Cray Inc.; Adrian Ludwin, Google; & Fei Guo, Alibaba 2019-11-19
  3. Enforcing Automatic mTLS with Linkerd and OPA GatekeeperIvan Sim, Buoyant & Rita Zhang, Microsoft 2019-11-19
  4. CAP_NET_RAW and ARP Spoofing in Your Cluster: It's Going Downhill From HereLiz Rice, Aqua Security 2019-11-19
  5. Redesigning Notary in a Multi-registry WorldJustin Cormack, Docker 2019-11-20
  6. Piloting Around the Rocks: Avoiding Threats in KubernetesRobert Tonic & Stefan Edwards, Trail of Bits 2019-11-20
  7. No video On the Security of Copying To and From Live ContainersAriel Zelivansky & Yuval Avrahami, Palo Alto Networks 2019-11-20
  8. Knative - The Security Platypus?Ariel Shuper, Aqua Security 2019-11-20
  9. Binary Authorization in KubernetesAysylu Greenberg, Google & Liron Levin, Palo Alto Networks 2019-11-20
  10. Securing Communication Between Meshes and Beyond with SPIFFE FederationEvan Gilman, Scytale & Oliver Liu, Google 2019-11-21
  11. Prepare to Be Boarded! A Tale of Kubernetes, Plunder, and CryptobootyJames Condon, Lacework 2019-11-21
  12. Kubernetes Policy Enforcement Using OPA At Goldman SachsMiguel Uzcategui, Goldman Sachs & Tim Hinrichs, Styra 2019-11-21
  13. Identity Bootstrapping in Multi-tenant Multi-cluster KubernetesManish Mehta, Volterra & Derek Suzuki, The Voleon Group 2019-11-21
  14. How Yelp Moved Security From the App to the Mesh with Envoy and OPADaniel Popescu, Yelp & Ben Plotnick, Cruise 2019-11-21
  15. How Kubernetes Components Communicate Securely in Your ClusterMaya Kaczorowski, Google 2019-11-21