Rogue No More: Securing Kubernetes with Node-Specific Restrictions
CNCF [Cloud Native Computing Foundation] via YouTube
Launch a New Career with Certificates from Google, IBM & Microsoft
2,000+ Free Courses with Certificates: Coding, AI, SQL, and More
Overview
Google, IBM & Meta Certificates — All 10,000+ Courses at 40% Off
One annual plan covers every course and certificate on Coursera. 40% off for a limited time.
Get Full Access
Learn about critical Kubernetes security enhancements in this technical conference talk that addresses the vulnerabilities of components running across multiple nodes. Discover how daemonset components performing node-specific actions can create security risks and potentially lead to cluster attacks or takeovers. Explore practical solutions through new security features focusing on bound service account tokens and their integration with validating admission policies to enforce per-node restrictions. Follow along as Microsoft's Anish Ramasekar and Apple's James Munnelly demonstrate implementation strategies for achieving robust node isolation, effectively preventing escalation attacks and strengthening cluster security.
Syllabus
Rogue No More: Securing Kubernetes with Node-Specific Restrictio... Anish Ramasekar & James Munnelly
Taught by
CNCF [Cloud Native Computing Foundation]