Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

CNCF [Cloud Native Computing Foundation]

Guardians of Multi-Tenancy - Enhanced Authorization to Prevent Lateral Node Escape

CNCF [Cloud Native Computing Foundation] via YouTube

Overview

Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Learn how to implement enhanced authorization mechanisms to prevent lateral node escape attacks in multi-tenant Kubernetes clusters through this conference talk from KubeCon + CloudNativeCon. Explore the critical security challenges faced by enterprise operations teams when managing cost-effective multi-tenant environments, particularly focusing on the vulnerabilities introduced by multiple daemonsets that can become attack vectors for cluster takeover. Discover recently introduced advanced security features from the SIG community, including CRD Field Selectors, Field and Label Selector Authorization, validating admission policy (VAP), and Structured Authorization Config, which enable more flexible authorization configurations for CRDs, kubelet, and other resources in multi-tenant settings. Gain insights from real-world node escape incidents and understand practical implementation strategies for these new security features. Master the use of Common Expression Language (CEL) to configure customized policies in Authorization Webhook and VAP systems, enabling more granular node-specific restrictions within your clusters to maximize security while maintaining operational efficiency.

Syllabus

Guardians of Multi-Tenancy: Enhanced Authorization To Prevent Lateral Node... Dahu Kuang & Cheng Gao

Taught by

CNCF [Cloud Native Computing Foundation]

Reviews

Start your review of Guardians of Multi-Tenancy - Enhanced Authorization to Prevent Lateral Node Escape

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.