Guardians of Multi-Tenancy - Enhanced Authorization to Prevent Lateral Node Escape
CNCF [Cloud Native Computing Foundation] via YouTube
Learn AI, Data Science & Business — Earn Certificates That Get You Hired
Learn Generative AI, Prompt Engineering, and LLMs for Free
Overview
AI, Data Science & Cloud Certificates from Google, IBM & Meta — 40% Off
One plan covers every Professional Certificate on Coursera. 40% off Coursera Plus Annual.
Unlock All Certificates
Learn how to implement enhanced authorization mechanisms to prevent lateral node escape attacks in multi-tenant Kubernetes clusters through this conference talk from KubeCon + CloudNativeCon. Explore the critical security challenges faced by enterprise operations teams when managing cost-effective multi-tenant environments, particularly focusing on the vulnerabilities introduced by multiple daemonsets that can become attack vectors for cluster takeover. Discover recently introduced advanced security features from the SIG community, including CRD Field Selectors, Field and Label Selector Authorization, validating admission policy (VAP), and Structured Authorization Config, which enable more flexible authorization configurations for CRDs, kubelet, and other resources in multi-tenant settings. Gain insights from real-world node escape incidents and understand practical implementation strategies for these new security features. Master the use of Common Expression Language (CEL) to configure customized policies in Authorization Webhook and VAP systems, enabling more granular node-specific restrictions within your clusters to maximize security while maintaining operational efficiency.
Syllabus
Guardians of Multi-Tenancy: Enhanced Authorization To Prevent Lateral Node... Dahu Kuang & Cheng Gao
Taught by
CNCF [Cloud Native Computing Foundation]