Get in Touch

Course Outline

Cluster Initialization

  • Implement network security policies to limit access at the cluster level
  • Conduct security configuration reviews of Kubernetes components (etcd, kubelet, kubedns, kubeapi) in accordance with CIS benchmarks
  • Configure Ingress objects with appropriate security controls
  • Safeguard node metadata and endpoints
  • Limit the utilization of and access to graphical user interface elements
  • Authenticate platform binaries prior to deployment

Cluster Reinforcement

  • Limit access to the Kubernetes API
  • Apply Role-Based Access Control to minimize exposure risks
  • Exercise strict oversight over service account usage, including disabling defaults and restricting permissions for new accounts
  • Ensure frequent updates to Kubernetes infrastructure

System Reinforcement

  • Reduce the host operating system footprint to decrease the attack surface
  • Limit Identity and Access Management (IAM) roles
  • Restrict external network access
  • Employ kernel hardening mechanisms, such as AppArmor and seccomp, appropriately

Microservice Vulnerability Mitigation

  • Establish OS-level security domains using Policy Specifications (PSP), Open Policy Agent (OPA), or security contexts
  • Manage Kubernetes secrets securely
  • Utilize container runtime sandboxes in multi-tenant configurations (e.g., gvisor, kata containers)
  • Enforce mutual TLS (mTLS) for encrypted communication between pods

Supply Chain Integrity

  • Minimize the footprint of base images
  • Secure the supply chain by whitelisting authorized image registries and performing image signing and validation
  • Conduct static analysis of user workloads, including Kubernetes resources and Dockerfiles
  • Scan images for known vulnerabilities

Monitoring, Logging, and Runtime Security

  • Perform behavioral analysis of system calls and file activities at both host and container levels to identify malicious conduct
  • Identify threats across physical infrastructure, applications, networks, data, users, and workloads
  • Detect all phases of attacks, regardless of origin or propagation method
  • Conduct thorough analytical investigations to identify unauthorized actors within the environment
  • Maintain container immutability during runtime
  • Leverage audit logs to monitor access patterns

Requirements

  • CKA (Certified Kubernetes Administrator) certification

Target Audience

  • Kubernetes practitioners
 21 Hours

Number of participants


Price per participant

Testimonials (3)

Upcoming Courses

Related Categories