Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Introduction
Overview of Kubernetes API and Security Features
- Access to HTTPS endpoints, Kubernetes API, nodes, and containers
- Kubernetes authentication and authorization mechanisms
Understanding Kubernetes Attack Vectors
- How attackers locate etcd ports, Kubernetes API, and other services
- Methods used to execute code within containers
- Privilege escalation techniques
- Case study: Analyzing the Tesla Kubernetes security breach
Setting Up Kubernetes
- Choosing the right distribution
- Installing Kubernetes
Managing Credentials and Secrets
- Credential lifecycle management
- Understanding secrets
- Distributing credentials securely
Controlling Access to the Kubernetes API
- Encrypting API traffic using TLS
- Implementing authentication for API servers
- Setting up authorization for various roles
Managing User and Workload Capabilities
- Understanding Kubernetes security policies
- Limiting resource consumption
- Restricting container privileges
- Controlling network access
Securing Node Access
- Segmenting workload access
Protecting Cluster Components
- Restricting etcd access
- Disabling unnecessary features
- Managing, revoking, and removing credentials and tokens
Securing Container Images
- Managing Docker and Kubernetes images
- Building secure images
Managing Cloud Resource Access
- Understanding cloud platform metadata
- Limiting permissions for cloud resources
Evaluating Third-Party Integrations
- Minimizing permissions granted to third-party software
- Assessing components capable of creating pods
Establishing a Security Policy
- Reviewing existing security profiles
- Developing a security model
- Cloud-native security considerations
- Additional best practices
Encrypting Data at Rest
- Encrypting backups
- Disk encryption
- Encrypting secret resources in etcd
Monitoring Activity
- Enabling audit logging
- Auditing and governing the software supply chain
- Subscribing to security alerts and updates
Summary and Conclusion
Requirements
- Previous experience working with Kubernetes
Audience
- DevOps engineers
- Developers
14 Hours
Testimonials (3)
About the microservices and how to maintenance kubernetes
Yufri Isnaini Rochmat Maulana - Bank Indonesia
Course - Advanced Platform Engineering: Scaling with Microservices and Kubernetes
How trainer deliver knowledge so effectively
Vu Thoai Le - Reply Polska sp. z o. o.
Course - Certified Kubernetes Administrator (CKA) - exam preparation
The knowledge and exchanges with Augustin