Загрузка страницы

Using eBPF to Bring Kubernetes-Aware Security to the Linux Kernel - Dan Wendlandt, Isovalent

Join us for Kubernetes Forums Seoul, Sydney, Bengaluru and Delhi - learn more at kubecon.io

Don't miss KubeCon + CloudNativeCon 2020 events in Amsterdam March 30 - April 2, Shanghai July 28-30 and Boston November 17-20! Learn more at kubecon.io. The conference features presentations from developers and end users of Kubernetes, Prometheus, Envoy, and all of the other CNCF-hosted projects

Using eBPF to Bring Kubernetes-Aware Security to the Linux Kernel - Dan Wendlandt, Isovalent

eBPF is a powerful Linux kernel technology that has recently become available in mainstream Linux distributions, enabling radically deeper visibility into and control over many aspects of operating system behavior. In this talk, we will cover the basics of eBPF and then dive into a hands-on exploration of use cases where eBPF-based technologies like Cilium and BCC can enable security visibility and isolation well beyond what is possible with traditional Linux security primitives, Examples include: 1. Auditing the set of syscalls made by users who access pods via "kubectl exec". 2. Network visibility and access control that distinguishes between a sidecar and primary container inside a single pod. 3. API-layer visibility into inter-service connectivity, even if the connection is encrypted using TLS.

https://sched.co/MPdW

Видео Using eBPF to Bring Kubernetes-Aware Security to the Linux Kernel - Dan Wendlandt, Isovalent канала CNCF [Cloud Native Computing Foundation]
Показать
Комментарии отсутствуют
Введите заголовок:

Введите адрес ссылки:

Введите адрес видео с YouTube:

Зарегистрируйтесь или войдите с
Информация о видео
22 мая 2019 г. 19:05:30
00:46:49
Другие видео канала
Faster MySQL with HTTP/3 and gRPCFaster MySQL with HTTP/3 and gRPCBackstage: Shaping the Future Of Developer Experience - Ben Lambert & Francesco Corti, SpotifyBackstage: Shaping the Future Of Developer Experience - Ben Lambert & Francesco Corti, SpotifyBeyond Namespaces: Virtual Clusters are the Future of Multi-Tenancy - Lukas Gentele, Loft LabsBeyond Namespaces: Virtual Clusters are the Future of Multi-Tenancy - Lukas Gentele, Loft LabsFrom Monolith to Microservices with Kubernetes and Linkerd - Mason Jones, Credit KarmaFrom Monolith to Microservices with Kubernetes and Linkerd - Mason Jones, Credit KarmaCNCF End User: Spotify Is Migrating from Homegrown Orchestration to KubernetesCNCF End User: Spotify Is Migrating from Homegrown Orchestration to KubernetesCNCF Live Webinar: Serverless - The next step in cloud nativeCNCF Live Webinar: Serverless - The next step in cloud nativeEnvoy Deep Dive – Matt Klein, Lyft (Intermediate Skill Level)Envoy Deep Dive – Matt Klein, Lyft (Intermediate Skill Level)Deep Dive: Cortex - Tom Wilkie, Grafana Labs & Bryan Boreham, WeaveworksDeep Dive: Cortex - Tom Wilkie, Grafana Labs & Bryan Boreham, WeaveworksTiKV: A Cloud Native Key-Value Database - Dongxu Huang & Nick Cameron, PingCAPTiKV: A Cloud Native Key-Value Database - Dongxu Huang & Nick Cameron, PingCAPOpenTelemetry or eBPF? That is the Question - Omid Azizi, New Relic (Pixie)OpenTelemetry or eBPF? That is the Question - Omid Azizi, New Relic (Pixie)Rightsize Your Pods with Vertical Pod Autoscaling - Beata Skiba, GoogleRightsize Your Pods with Vertical Pod Autoscaling - Beata Skiba, GoogleCNL: Secure workload identities with SPIFFE, cert-manager, trust-managerCNL: Secure workload identities with SPIFFE, cert-manager, trust-managerScaling Java apps to zero with GraalVM Native ImageScaling Java apps to zero with GraalVM Native ImageKubernetes Networking at Scale - Laurent Bernaille, Datadog & Bowei Du, GoogleKubernetes Networking at Scale - Laurent Bernaille, Datadog & Bowei Du, GoogleWindows HostProcess Containers For Configuration And Beyond - James Sturtevant & Mark RossettiWindows HostProcess Containers For Configuration And Beyond - James Sturtevant & Mark RossettiSponsored Keynote: Kubernetes as the Control Plane for the Hybrid Cloud - Clayton ColemanSponsored Keynote: Kubernetes as the Control Plane for the Hybrid Cloud - Clayton ColemanIntro: Harbor - Henry Zhang & Steven Ren, VMwareIntro: Harbor - Henry Zhang & Steven Ren, VMwareEdge Computing using K3s on Raspberry Pi - Jeff Spahr, LenovoEdge Computing using K3s on Raspberry Pi - Jeff Spahr, LenovoTikTok’s Story: How To Manage a Thousand Applications on Edge With Argo CD - Qingkun Li & Jesse SuenTikTok’s Story: How To Manage a Thousand Applications on Edge With Argo CD - Qingkun Li & Jesse SuenCert-Manager Beyond Ingress – Exploring the Variety of Use Cases - Matthew Bates, JetstackCert-Manager Beyond Ingress – Exploring the Variety of Use Cases - Matthew Bates, JetstackSupercharge the Kubernetes Experience with Kubernetes DashboardSupercharge the Kubernetes Experience with Kubernetes Dashboard
Яндекс.Метрика