Course Outline
Introduction
Overview of Kubernetes API and Security Capabilities
- Access to HTTPS endpoints, Kubernetes API, nodes, and containers
- Kubernetes Authentication and Authorization mechanisms
Adversarial Techniques Against Clusters
- Methods used by threat actors to identify etcd ports, Kubernetes API, and auxiliary services
- Techniques for executing unauthorized code within containers
- Processes for privilege escalation by attackers
- Case study: Exposure of Tesla's Kubernetes cluster
Kubernetes Deployment Configuration
- Selection of distribution versions
- Installation procedures for Kubernetes
Management of Credentials and Secrets
- The lifecycle of credentials
- Definitions and characteristics of secrets
- Distribution strategies for credentials
Regulating Access to the Kubernetes API
- Securing API traffic via TLS encryption
- Establishing authentication for API servers
- Implementing role-based authorization
Restriction of User and Workload Capabilities
- Interpretation of Kubernetes policies
- Constraints on resource consumption
- Limitations on container privileges
- Restrictions on network connectivity
Regulation of Node Access
- Isolation of workload access
Protection of Cluster Components
- Restriction of access to etcd
- Deactivation of unnecessary features
- Modification, removal, and revocation of credentials and tokens
Securing Container Images
- Administration of Docker and Kubernetes images
- Construction of secure images
Regulation of Access to Cloud Resources
- Comprehension of cloud platform metadata
- Limitation of permissions to cloud resources
Assessment of Third-Party Integrations
- Minimization of permissions assigned to third-party software
- Evaluation of components capable of creating pods
Formulation of Security Policy
- Assessment of the current security posture
- Development of a security model
- Cloud-native security considerations
- Additional best practices
Encryption of Inactive Data
- Encryption of backups
- Encryption of entire disks
- Encryption of secret resources in etcd
Surveillance of Activity
- Activation of audit logging
- Audit and governance of the software supply chain
- Subscription to security alerts and updates
Conclusion and Summary
Requirements
- Prior experience working with Kubernetes
Target Audience
- DevOps engineers
- Developers
Testimonials (4)
basic understanding of container/kubernetes and how they interact features of the openshift plattform
Eric Scholze - NOW IT GmbH
Course - Introduction to Containers, Kubernetes & OpenShift
About the microservices and how to maintenance kubernetes
Yufri Isnaini Rochmat Maulana - Bank Indonesia
Course - Advanced Platform Engineering: Scaling with Microservices and Kubernetes
How trainer deliver knowledge so effectively
Vu Thoai Le - Reply Polska sp. z o. o.
Course - Certified Kubernetes Administrator (CKA) - exam preparation
The knowledge and exchanges with Augustin