Session
You Don't Own the Image, But You Own the Risk: Securing Third-Party Containers
The common use of third-party container images has created a systemic security challenge for the cloud-native ecosystem. Common practice is to detect problems and delegate remediation, creating persistent exposure. This session examines the security lifecycle through static (registry-stored) and dynamic (runtime) perspectives. The speaker covers various real-world scenarios on third party images consumption. All approaches introduce trade-offs: rebuilds increase complexity and break signatures, waiting creates exposure windows, minimal bases limit compatibility, runtime protection adds overhead without removing vulnerabilities. Harbor's native Copacetic integration provides an alternative automated package patching. We demonstrate vulnerability detection to patch application flows, covering manual workflows for critical CVEs and automated pipelines. Attendees evaluate this against existing strategies with examples of complexity reduction, MTTR improvements, and integration patterns.
Vadim Bauer
Cloud Native builder in the Clouds with Kubernetes. CNCF Project Harbor maintainer.
Zürich, Switzerland
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top