Session

Your Pods Are Leaking: Bidirectional DLP Sidecars for Kubernetes

What happens when a misconfigured pod sends customer SSNs to an external API? Or when a compromised container exfiltrates secrets? Perimeter DLP tools can't see inside your pods, and service meshes handle routing - not content inspection.

This talk shows a practical approach to pod-level data leak prevention using ingress and egress sidecar containers. Using regex-based pattern matching deployed via Kubernetes ConfigMaps, the sidecars detect and block sensitive data - PII, credentials, even SQL injection attempts — in real time with under 5ms overhead and zero app code changes. The architecture is also extensible to ML-based detection for identifying patterns that regex alone cannot catch.

Attendees will see a live demo of an egress sidecar catching a credit card number in an outbound API call, learn how to dynamically update DLP policies without pod restarts, and understand how this lightweight approach compares to service meshes for content-aware security.

Umang Kedia

Principal Cloud Developer, HPE

Salt Lake City, Utah, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top