Session
Pods, Privileges, and Other Things That Keep Security Engineers Up at Night
This session is designed for security, DevOps, and cloud infrastructure engineers who want a practical understanding of Kubernetes security, without getting overwhelmed about what they might have missed.
We will cover:
* What is Kubernetes and why does it matter: why it has become the backbone of modern infrastructure, and why securing it is not optional
* Why pods and containers are a big deal: share examples on how minor configuration missteps can significantly expose critical workloads.
* Common mistakes and misconfigurations to avoid issues such as overly permissive service accounts, deployment to default namespaces, and unverified images.
* How Kubernetes handles security by default: discuss built-in security components such as RBAC, TLS, and container images integrity.
* Practical ways to secure your clusters: discuss how to utilize open-source tools (like Falco, Trivy) and best practices for logging and monitoring to protect your clusters
Key Takeaways
* Understand Kubernetes architecture and why it is crucial to secure your workloads properly
* The built-in security features in Kubernetes and their limitations
* Recognize the common misconfigurations and learn how to avoid them
* Gain practical, actionable tips and essential tools to harden your cluster
Jie Wu
Senior Security Engineer at Shopify
New York City, New York, United States
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top