YoVDO

Extending Kubernetes with Storage Transformers

Offered By: Linux Foundation via YouTube

Tags

Kubernetes Courses Encryption Courses Cloud Security Courses Configuration Management Courses Secrets Management Courses etcd Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore the architecture and implementation of Storage Transformers in Kubernetes through this demo-heavy conference talk. Learn how to extend Kubernetes by leveraging storage transformers, which are invoked by the kube-apiserver before resources are written to or read from etcd. Discover appropriate scenarios for using storage transformers as an extensibility point, including encrypting secrets at rest. Follow along as the speaker demonstrates the step-by-step process of implementing a transformer interface, creating YAML config structures, and configuring KMS encryption. Gain insights into re-using envelope transformers, adding configurable DEK types to KMS plugins, and choosing the right KMS provider for your needs.

Syllabus

Intro
Extensibility at the RPC layer
Motivating Problem - Encrypting Secrets at Rest
Implement Transformer Interface
Step #2: Create your YAML config structure
Add your type to ProviderConfiguration
Prefix Transformer
Define your prefix
Add Init logic for your transformer
Re-using Envelope Transformer
KMS encryption configuration
add configurable DEK type to KMS plugin
teach KMS plugin about your new DEK type
choose your KMS provider and plugin
Summary


Taught by

Linux Foundation

Tags

Related Courses

Kubernetes
YouTube
Advanced Kubernetes: 1 Core Concepts
LinkedIn Learning
Kubernetes the Hard Way
A Cloud Guru
Unterminating Kubernetes Resources - Avoiding Unintentional Data Loss
Cloud Native Skunkworks via YouTube
Implementing Distributed Consensus
USENIX via YouTube