YoVDO

A Wander Through the World of Container Security

Offered By: OWASP Foundation via YouTube

Tags

Conference Talks Courses Cybersecurity Courses Cloud Computing Courses Docker Courses Kubernetes Courses Containerization Courses RBAC Courses Container Security Courses

Course Description

Overview

Explore the intricacies of container security in this 52-minute conference talk presented by Anais Urlichs for the OWASP Foundation. Delve into the fundamentals of containerization, starting with the concept of turning processes into contained processes and understanding Docker as a command execution service. Gain insights into Kubernetes architecture and its role in container orchestration. Examine the layered structure of the container stack and learn about potential vulnerabilities, including container breakout CVEs. Investigate the Kubernetes control plane, networking complexities, and the role of cluster nodes as routers. Analyze specific security concerns such as CVE-2020-8554 and its impact on services. Discuss the future landscape of network attacks in containerized environments. Address user management challenges in Kubernetes and explore the intricacies of Role-Based Access Control (RBAC). Conclude with a comprehensive overview of container security best practices and emerging trends in the field.

Syllabus

Intro
About Rory
Turning a process into a contained process
Docker == Command Execution As A Service
So, What is Kubernetes?
Container Stack - A Layer Cake
Container Breakout CVES Kubernetes Control Plane
Kubernetes Networking Fun
Cluster nodes are routers
CVE-2020-8554 - Attack of the services
The Future for network attacks
Kubernetes - Where's my users?
RBAC - The restless verbs
Conclusion


Taught by

OWASP Foundation

Related Courses

Fundamentals of Containers, Kubernetes, and Red Hat OpenShift
Red Hat via edX
Configuration Management for Containerized Delivery
Microsoft via edX
Getting Started with Google Kubernetes Engine - Español
Google Cloud via Coursera
Getting Started with Google Kubernetes Engine - 日本語版
Google Cloud via Coursera
Architecting with Google Kubernetes Engine: Foundations en Español
Google Cloud via Coursera