Session

The Day One Pod Got Compromised: A Zero Trust Story on Amazon EKS

It's Monday morning. Your team has just deployed a brand-new application on Amazon EKS. Dashboards are green, pods are healthy, and customers are already placing orders.

Then, a single pod gets compromised.

What happens next?

Can the attacker access Kubernetes Secrets? Move laterally across namespaces? Reach your databases? Or does the attack stop at that very first pod?

In this story-driven session, we'll walk through a realistic Kubernetes security incident from the attacker's perspective. We'll uncover how a single vulnerable workload can become a cluster-wide security event—and how implementing Zero Trust principles can completely change the outcome.


ather than treating Zero Trust as a theoretical security framework, we'll explore practical, production-ready techniques for securing Amazon EKS using Kubernetes-native capabilities and cloud-native best practices, including:

IAM Roles for Service Accounts (IRSA)
Kubernetes RBAC & Service Accounts
Network Policies
Admission Controllers
Policy as Code with Kyverno / OPA
Service Mesh with mTLS (Istio/Linkerd)
Runtime threat detection and continuous monitoring

We'll replay the same attack twice—first in a traditionally secured cluster, and then in a Zero Trust-enabled Amazon EKS environment—to demonstrate how identity, least privilege, and workload isolation can dramatically reduce an attacker's blast radius.

Whether you're running production Kubernetes clusters or just beginning your cloud-native security journey, you'll leave with a practical roadmap for implementing Zero Trust on Amazon EKS and the confidence to answer one critical question:

"If one pod is compromised today, how far could an attacker really go?"

Varsha Verma

AWS Community Builder | Lead Cloud Engineer at Accenture | Public Speaker | Technical Blogger | Helping Individuals with Cloud and DevOps

Hyderābād, India

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top