Get in Touch

Course Outline

Introduction

Overview of Kubernetes API and Security Capabilities

  • Access to HTTPS endpoints, Kubernetes API, nodes, and containers
  • Kubernetes Authentication and Authorization mechanisms

Adversarial Techniques Against Clusters

  • Methods used by threat actors to identify etcd ports, Kubernetes API, and auxiliary services
  • Techniques for executing unauthorized code within containers
  • Processes for privilege escalation by attackers
  • Case study: Exposure of Tesla's Kubernetes cluster

Kubernetes Deployment Configuration

  • Selection of distribution versions
  • Installation procedures for Kubernetes

Management of Credentials and Secrets

  • The lifecycle of credentials
  • Definitions and characteristics of secrets
  • Distribution strategies for credentials

Regulating Access to the Kubernetes API

  • Securing API traffic via TLS encryption
  • Establishing authentication for API servers
  • Implementing role-based authorization

Restriction of User and Workload Capabilities

  • Interpretation of Kubernetes policies
  • Constraints on resource consumption
  • Limitations on container privileges
  • Restrictions on network connectivity

Regulation of Node Access

  • Isolation of workload access

Protection of Cluster Components

  • Restriction of access to etcd
  • Deactivation of unnecessary features
  • Modification, removal, and revocation of credentials and tokens

Securing Container Images

  • Administration of Docker and Kubernetes images
  • Construction of secure images

Regulation of Access to Cloud Resources

  • Comprehension of cloud platform metadata
  • Limitation of permissions to cloud resources

Assessment of Third-Party Integrations

  • Minimization of permissions assigned to third-party software
  • Evaluation of components capable of creating pods

Formulation of Security Policy

  • Assessment of the current security posture
  • Development of a security model
  • Cloud-native security considerations
  • Additional best practices

Encryption of Inactive Data

  • Encryption of backups
  • Encryption of entire disks
  • Encryption of secret resources in etcd

Surveillance of Activity

  • Activation of audit logging
  • Audit and governance of the software supply chain
  • Subscription to security alerts and updates

Conclusion and Summary

Requirements

  • Prior experience working with Kubernetes

Target Audience

  • DevOps engineers
  • Developers
 14 Hours

Number of participants


Price per participant

Testimonials (4)

Upcoming Courses

Related Categories