Session

The Day One Pod Got Compromised: A Zero Trust Story

It's Monday morning. A brand-new Kubernetes application has just been deployed to production. The dashboards are green, traffic is flowing, and everything looks healthy.

Then a single vulnerable pod gets compromised.

What happens next?

Can the attacker access Kubernetes Secrets? Move laterally across namespaces? Reach the database? Or does the attack end with that one pod?

This session takes the audience on the journey of a real-world Kubernetes compromise, following the attacker's path through a cluster and demonstrating how each stage of the attack can be stopped using Zero Trust principles.

Rather than treating Zero Trust as another security buzzword, we'll explore how Kubernetes-native capabilities—including RBAC, Service Accounts, Network Policies, admission controllers, Policy as Code (OPA/Kyverno), and service meshes with mTLS—work together to reduce the blast radius of an attack.

The session focuses on practical implementation patterns, common misconfigurations, and production-ready best practices that platform engineers, DevOps teams, and security practitioners can start applying immediately.


By the end of the talk, attendees will understand not only what Zero Trust is, but how to design Kubernetes clusters that assume breach, verify every workload, and stop attackers before a single compromised pod becomes a full-cluster incident.

Varsha Verma

AWS Community Builder | Lead Cloud Engineer at Accenture | Public Speaker | Technical Blogger | Helping Individuals with Cloud and DevOps

Hyderābād, India

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top