Fixing a misconfigured Kubernetes Cluster by Rob Kenefeck

  • First big docker project was to separately build and test application, hardware and OS

  • First k8s job was focused on making tech work, not the security model around it

  • Still considers k8s in Australia to be fairly bleeding edge

  • OWASP Kubernetes Top 10

  • First released in 2022

  • New list version out soon

  • VMs vs Containers

  • People Treat Containers like they are VMs

  • Lots of things in Linux are not namespace in containers

  • Kernel Modules, /sys , /dev

  • Docker Damon will often run as root

  • Shared Kernel

  • Container Security: Opportunities

  • Hardened Kernels – GRSEC, PAX

  • Security Policies/Whitelisting – Seccomp, AppArmor, SELinux

  • Container Security

  • Drop to unprivileged user in Docker

  • Reduce Attack surface –…

Similar Posts

Loading similar posts...

Keyboard Shortcuts

Navigation
Next / previous item
j/k
Open post
oorEnter
Preview post
v
Post Actions
Love post
a
Like post
l
Dislike post
d
Undo reaction
u
Recommendations
Add interest / feed
Enter
Not interested
x
Go to
Home
gh
Interests
gi
Feeds
gf
Likes
gl
History
gy
Changelog
gc
Settings
gs
Browse
gb
Search
/
General
Show this help
?
Submit feedback
!
Close modal / unfocus
Esc

Press ? anytime to show this help