Course Outline
Introduction
An overview of the Kubernetes API and its security capabilities
- Accessing HTTPS endpoints, the Kubernetes API, nodes, and containers
- Leveraging Kubernetes Authentication and Authorization features
Understanding Threat Vectors
- How attackers discover exposed etcd ports, APIs, and services
- Methods used to execute code within containers
- Techniques for privilege escalation
- Case study: The exposure of Tesla’s Kubernetes cluster
Kubernetes Deployment
- Selecting an appropriate distribution
- Installing the Kubernetes environment
Managing Credentials and Secrets
- The credential lifecycle
- Concepts surrounding secrets
- Secure distribution of credentials
API Access Control
- Securing API traffic using TLS encryption
- Configuring authentication for API servers
- Implementing role-based authorization
Restricting User and Workload Privileges
- Interpreting Kubernetes policies
- Managing resource usage limits
- Constraining container privileges
- Controlling network access
Node Access Management
- Isolating workload access
Safeguarding Cluster Components
- Limiting access to etcd
- Disabling unnecessary features
- Rotating, removing, and revoking credentials and tokens
Container Image Security
- Overseeing Docker and Kubernetes images
- Creating hardened images
Cloud Resource Access Control
- Analyzing cloud platform metadata
- Restricting permissions for cloud resources
Assessing Third-Party Integrations
- Minimizing permissions assigned to external software
- Evaluating components capable of creating pods
Defining a Security Policy
- Auditing the current security posture
- Designing a security model
- Considering cloud-native security factors
- Adopting additional best practices
Data Encryption at Rest
- Encrypting backup files
- Full-disk encryption strategies
- Encrypting secret resources stored in etcd
Activity Monitoring
- Activating audit logging
- Overseeing the software supply chain
- Staying informed via security alerts and updates
Summary and Conclusion
Requirements
- Prior hands-on experience with Kubernetes
Audience
- DevOps Engineers
- Developers
Testimonials (4)
basic understanding of container/kubernetes and how they interact features of the openshift plattform
Eric Scholze - NOW IT GmbH
Course - Introduction to Containers, Kubernetes & OpenShift
About the microservices and how to maintenance kubernetes
Yufri Isnaini Rochmat Maulana - Bank Indonesia
Course - Advanced Platform Engineering: Scaling with Microservices and Kubernetes
How trainer deliver knowledge so effectively
Vu Thoai Le - Reply Polska sp. z o. o.
Course - Certified Kubernetes Administrator (CKA) - exam preparation
The knowledge and exchanges with Augustin