Загрузка страницы

Hardware-based KMS Plug-in to Protect Secrets in Kubernetes - Raghu Yeluri & Haidong Xia, Intel

Join us for Kubernetes Forums Seoul, Sydney, Bengaluru and Delhi - learn more at kubecon.io

Don't miss KubeCon + CloudNativeCon 2020 events in Amsterdam March 30 - April 2, Shanghai July 28-30 and Boston November 17-20! Learn more at kubecon.io. The conference features presentations from developers and end users of Kubernetes, Prometheus, Envoy, and all of the other CNCF-hosted projects

Hardware-based KMS Plug-in to Protect Secrets in Kubernetes - Raghu Yeluri & Haidong Xia, Intel

Secrets are a key pillar of K8S security, and K8S 1.10+ enhanced the protection of secrets at-rest in the etcd, with support for an external KMS (via KMS plug-ins), and supporting envelope encryption. However, the secret encryption keys (DEKs/KEK) are in the clear in memory of the K8S Master in the KMS plug-ins (during execution). An attacker with privilege access to k8S master node/host, can read the keys from memory, access secrets, compromising data & k8s cluster. This session proposes a solution (with a quick demo) to add a new KMS plug-in that leverages hardware based TEE (Trusted execution environment – like Intel SGX) to ensure that the keys, and the encryption of the secrets, are protected by the CPU on the master, addressing the threat vector mentioned. It enumerates multiple options for the integration with KMS, articulating the the trade-offs of the approaches.

https://sched.co/UaZ2

Видео Hardware-based KMS Plug-in to Protect Secrets in Kubernetes - Raghu Yeluri & Haidong Xia, Intel канала CNCF [Cloud Native Computing Foundation]
Показать
Комментарии отсутствуют
Введите заголовок:

Введите адрес ссылки:

Введите адрес видео с YouTube:

Зарегистрируйтесь или войдите с
Информация о видео
23 ноября 2019 г. 1:41:58
00:38:10
Другие видео канала
TiKV: A Cloud Native Key-Value Database - Dongxu Huang & Nick Cameron, PingCAPTiKV: A Cloud Native Key-Value Database - Dongxu Huang & Nick Cameron, PingCAPOpenTelemetry or eBPF? That is the Question - Omid Azizi, New Relic (Pixie)OpenTelemetry or eBPF? That is the Question - Omid Azizi, New Relic (Pixie)Kubernetes Networking at Scale - Laurent Bernaille, Datadog & Bowei Du, GoogleKubernetes Networking at Scale - Laurent Bernaille, Datadog & Bowei Du, GoogleCluster API Deep Dive - Katie Gamanji, American Express & Carlos Panato, MattermostCluster API Deep Dive - Katie Gamanji, American Express & Carlos Panato, MattermostHow to Be 10x SRE? A Deep Dive to Prometheus Operator - Jayapriya Pai & Haoyu Sun, Red HatHow to Be 10x SRE? A Deep Dive to Prometheus Operator - Jayapriya Pai & Haoyu Sun, Red HatBuildKit CLI for kubectl: A New Way to Build Container Images - Daniel Hiltgen & Patrick DevineBuildKit CLI for kubectl: A New Way to Build Container Images - Daniel Hiltgen & Patrick DevineEdge Computing using K3s on Raspberry Pi - Jeff Spahr, LenovoEdge Computing using K3s on Raspberry Pi - Jeff Spahr, LenovoTikTok’s Story: How To Manage a Thousand Applications on Edge With Argo CD - Qingkun Li & Jesse SuenTikTok’s Story: How To Manage a Thousand Applications on Edge With Argo CD - Qingkun Li & Jesse SuenDeploying VNFs with Kubernetes pods and VMsDeploying VNFs with Kubernetes pods and VMsRunning distributed load tests with the Grafana k6-operatorRunning distributed load tests with the Grafana k6-operatorVolcano – Cloud Native Batch System for AI, BigData and HPC - William (LeiBo) WangVolcano – Cloud Native Batch System for AI, BigData and HPC - William (LeiBo) WangMeshery - The Service Mesh ManagerMeshery - The Service Mesh ManagerKeynote: Cloud Native Superpowers with eBPF by Liz RiceKeynote: Cloud Native Superpowers with eBPF by Liz RiceKeynote: Smooth Operator♪: Large Scale Automated Storage with... - Celina Ward & Matt SchallertKeynote: Smooth Operator♪: Large Scale Automated Storage with... - Celina Ward & Matt SchallertKubernetes Configuration - Auditing for Enterprise Best Practices Through Open Source ToolingKubernetes Configuration - Auditing for Enterprise Best Practices Through Open Source ToolingOpen Policy Agent (OPA) Intro & Deep Dive - Anders Eknert, Styra & Will Beason, GoogleOpen Policy Agent (OPA) Intro & Deep Dive - Anders Eknert, Styra & Will Beason, GoogleDeaf and Hard of Hearing WG Meeting - 2024-06-27Deaf and Hard of Hearing WG Meeting - 2024-06-27Seeing is Believing: Debugging with Ephemeral Containers - Aaron Alpar, KastenSeeing is Believing: Debugging with Ephemeral Containers - Aaron Alpar, KastenServing Machine Learning Models at Scale Using KServe - Yuzhui Liu, BloombergServing Machine Learning Models at Scale Using KServe - Yuzhui Liu, BloombergImproving GPU Utilization using Kubernetes - Maulin Patel & Pradeep Venkatachalam, GoogleImproving GPU Utilization using Kubernetes - Maulin Patel & Pradeep Venkatachalam, GoogleCloud Native Apps with Server-Side WebAssembly - Liam Randall, CosmonicCloud Native Apps with Server-Side WebAssembly - Liam Randall, Cosmonic
Яндекс.Метрика