Isolate the Users! Supporting User Namespaces in K8s for Increased Security
CNCF [Cloud Native Computing Foundation] via YouTube
Learn AI, Data Science & Business — Earn Certificates That Get You Hired
Get 20% off all career paths from fullstack to AI
Overview
Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This talk explains how Linux user namespaces map container user and group IDs so that a process running as root in a container runs as a non-root user on the host. It covers efforts to support user namespaces in Kubernetes, including volume-related challenges and approaches such as shiftfs and idmapped mounts.
Syllabus
Introduction
The Problem
Mitigations
What are username spaces
ID mapping
Isolate capability
Example
History
Challenges
Solution
ID Mapping Modes
Comparison
Demonstration
Next steps
Taught by
CNCF [Cloud Native Computing Foundation]