Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Cluster Initialization
- Implement network security policies to limit access at the cluster level
- Conduct security configuration reviews of Kubernetes components (etcd, kubelet, kubedns, kubeapi) in accordance with CIS benchmarks
- Configure Ingress objects with appropriate security controls
- Safeguard node metadata and endpoints
- Limit the utilization of and access to graphical user interface elements
- Authenticate platform binaries prior to deployment
Cluster Reinforcement
- Limit access to the Kubernetes API
- Apply Role-Based Access Control to minimize exposure risks
- Exercise strict oversight over service account usage, including disabling defaults and restricting permissions for new accounts
- Ensure frequent updates to Kubernetes infrastructure
System Reinforcement
- Reduce the host operating system footprint to decrease the attack surface
- Limit Identity and Access Management (IAM) roles
- Restrict external network access
- Employ kernel hardening mechanisms, such as AppArmor and seccomp, appropriately
Microservice Vulnerability Mitigation
- Establish OS-level security domains using Policy Specifications (PSP), Open Policy Agent (OPA), or security contexts
- Manage Kubernetes secrets securely
- Utilize container runtime sandboxes in multi-tenant configurations (e.g., gvisor, kata containers)
- Enforce mutual TLS (mTLS) for encrypted communication between pods
Supply Chain Integrity
- Minimize the footprint of base images
- Secure the supply chain by whitelisting authorized image registries and performing image signing and validation
- Conduct static analysis of user workloads, including Kubernetes resources and Dockerfiles
- Scan images for known vulnerabilities
Monitoring, Logging, and Runtime Security
- Perform behavioral analysis of system calls and file activities at both host and container levels to identify malicious conduct
- Identify threats across physical infrastructure, applications, networks, data, users, and workloads
- Detect all phases of attacks, regardless of origin or propagation method
- Conduct thorough analytical investigations to identify unauthorized actors within the environment
- Maintain container immutability during runtime
- Leverage audit logs to monitor access patterns
Requirements
- CKA (Certified Kubernetes Administrator) certification
Target Audience
- Kubernetes practitioners
21 Hours
Testimonials (3)
basic understanding of container/kubernetes and how they interact features of the openshift plattform
Eric Scholze - NOW IT GmbH
Course - Introduction to Containers, Kubernetes & OpenShift
About the microservices and how to maintenance kubernetes
Yufri Isnaini Rochmat Maulana - Bank Indonesia
Course - Advanced Platform Engineering: Scaling with Microservices and Kubernetes
The training met expectations with its clear explanations, real-world examples, and hands-on labs that made complex topics easy to understand. It provided valuable insights into container orchestration, security, scaling and many other advanced topics.