YoVDO

Achieving Least Privilege Access in Kubernetes

Offered By: CNCF [Cloud Native Computing Foundation] via YouTube

Tags

Kubernetes Security Courses Compliance Courses Role-Based Access Control Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore the fundamentals of Kubernetes permissions, access, and Role-Based Access Control (RBAC) in this 56-minute webinar presented by Aqua Security and Apolicy. Learn about RBAC concepts, how access works in Kubernetes, and methods for defining and enforcing access policies. Discover techniques for assigning roles with the minimum necessary access level to perform specific jobs. Gain practical knowledge on achieving least-privilege access in Kubernetes environments. Cover topics such as Kubernetes Roles, Resources, Subjects, Role Bindings, and advanced concepts like Default Aggregated Cluster Roles. Understand common pitfalls, audit processes, and key methods for managing permissions effectively. Join presenters Eran Leib from Apolicy and Daniel Pacak from Aqua Security as they address common security and compliance challenges in dynamic Kubernetes environments.

Syllabus

Introduction
Agenda
Introductions
Rolebased access control
Ongoing maintenance
A common misconception
Kubernetes Roles
What are Roles
What are Resources
NonResources
Subjects
Kubernetes Subjects
Kubernetes Role Bindings
Recap
CanI
Understanding Effective Access
Examples
Advanced Topics
Default
Aggregated Cluster Roles
Role Binding
Common Pitfalls
Autopopulated Groups
List Privilege
Key Method
The compromise
The audit
Steps
Summary
Current Context
Client Certificate
System Masters Group
Service Accounts
Code Token
Audit Log
Cluster Role
Default Service Account
Service Account Flag
Questions


Taught by

CNCF [Cloud Native Computing Foundation]

Related Courses

Security Best Practices in Google Cloud
Google Cloud via Coursera
Architecting with Google Kubernetes Engine: Production en Français
Google Cloud via Coursera
Configuring and Managing Kubernetes Security
Pluralsight
Security Best Practices in Google Cloud
Pluralsight
Kubernetes Security: Cluster Hardening
Pluralsight