Securing Kubernetes Secrets (Cloud Next '19)
Secrets are a key pillar of Kubernetes’ security model, used internally (e.g. service accounts) and by users (e.g. API keys), but did you know they are stored in plaintext? That’s right, by default all Kubernetes secrets are base64 encoded and stored as plaintext in etcd. Anyone with access to the etcd cluster has access to all your Kubernetes secrets.
Thankfully there are better ways. This lecture provides an overview of different techniques for more securely managing secrets in Kubernetes, including secrets encryption, KMS plugins, and tools like HashiCorp Vault. Attendees will learn the trade-offs of each approach to make better decisions on how to secure their Kubernetes clusters.
Securing Kubernetes Secrets → http://bit.ly/2TYdHiS
Application-layer Secrets Encryption → http://bit.ly/2Uhn7v7
Watch more:
Next '19 Hybrid Cloud Sessions here → https://bit.ly/Next19HybridCloud
Next ‘19 All Sessions playlist → https://bit.ly/Next19AllSessions
Subscribe to the GCP Channel → https://bit.ly/GCloudPlatform
Speaker(s): Seth Vargo, Alexandr Tcherniakhovski
Session ID: HYB200
product:Kubernetes Engine,Cloud KMS; fullname:Alexandr Tcherniakhovski,Seth Vargo; event: Google Cloud Next 2019; re_ty: Publish; product: Cloud - Containers - Google Kubernetes Engine (GKE); fullname: Seth Vargo;
Видео Securing Kubernetes Secrets (Cloud Next '19) канала Google Cloud Tech
Thankfully there are better ways. This lecture provides an overview of different techniques for more securely managing secrets in Kubernetes, including secrets encryption, KMS plugins, and tools like HashiCorp Vault. Attendees will learn the trade-offs of each approach to make better decisions on how to secure their Kubernetes clusters.
Securing Kubernetes Secrets → http://bit.ly/2TYdHiS
Application-layer Secrets Encryption → http://bit.ly/2Uhn7v7
Watch more:
Next '19 Hybrid Cloud Sessions here → https://bit.ly/Next19HybridCloud
Next ‘19 All Sessions playlist → https://bit.ly/Next19AllSessions
Subscribe to the GCP Channel → https://bit.ly/GCloudPlatform
Speaker(s): Seth Vargo, Alexandr Tcherniakhovski
Session ID: HYB200
product:Kubernetes Engine,Cloud KMS; fullname:Alexandr Tcherniakhovski,Seth Vargo; event: Google Cloud Next 2019; re_ty: Publish; product: Cloud - Containers - Google Kubernetes Engine (GKE); fullname: Seth Vargo;
Видео Securing Kubernetes Secrets (Cloud Next '19) канала Google Cloud Tech
Показать
Комментарии отсутствуют
Информация о видео
Другие видео канала
![Kubernetes Security Best Practices - Ian Lewis, Google](https://i.ytimg.com/vi/wqsUfvRyYpw/default.jpg)
![Secrets in Kubernetes | Coupon: UDEMYNOV20 | Udemy: Kubernetes Made Easy | Kubernetes Tutorial](https://i.ytimg.com/vi/tZEKGNnvBzg/default.jpg)
![Base64 is not encryption A better story for Kubernetes Secrets](https://i.ytimg.com/vi/f4Ru6CPG1z4/default.jpg)
![Kubernetes Secret Management Explained](https://i.ytimg.com/vi/o36yTfGDmZ0/default.jpg)
![Kubernetes Security Best Practices 2021 (From Container Specialist)](https://i.ytimg.com/vi/XUFVT8bGJhw/default.jpg)
![Kubernetes Secrets in 5 Minutes!](https://i.ytimg.com/vi/cQAEK9PBY8U/default.jpg)
![](https://i.ytimg.com/vi/n1r6Pcl4Zc0/default.jpg)
![Deep Dive: Flux the GitOps Operator for Kubernetes - Stefan Prodan, Weaveworks](https://i.ytimg.com/vi/Fs_Oz-RzWWI/default.jpg)
![Seccomp Security Profiles and You: A Practical Guide - Duffie Cooley, VMware](https://i.ytimg.com/vi/OPuu8wsu2Zc/default.jpg)
![[ Kube 14 ] Using Secrets in Kubernetes](https://i.ytimg.com/vi/ch9YlQZ4xTc/default.jpg)
![Bitnami Sealed Secrets - How To Store Kubernetes Secrets In Git Repositories](https://i.ytimg.com/vi/xd2QoV6GJlc/default.jpg)
![Cloud Security Command Center: Control of Your Vulnerabilities on GCP (Cloud Next '18)](https://i.ytimg.com/vi/grlP6gVqaOk/default.jpg)
![Deploying Spring Boot in Kubernetes | Google Kubernetes Engine | K8s Primers | Tech Primers](https://i.ytimg.com/vi/jSYxW_c3M_E/default.jpg)
![Introduction to HashiCorp Vault on Kubernetes for beginners](https://i.ytimg.com/vi/L_o_CG_AGKA/default.jpg)
![Kubernetes Operators Explained](https://i.ytimg.com/vi/i9V4oCa5f9I/default.jpg)
![Organizing the YAML mess with Kustomize - Florian Assmus](https://i.ytimg.com/vi/1fCAwFGX38U/default.jpg)
![Hacking and Hardening Kubernetes Clusters by Example [I] - Brad Geesaman, Symantec](https://i.ytimg.com/vi/vTgQLzeBfRU/default.jpg)
![Scalable and Manageable: A Deep-Dive Into GKE Networking Best Practices (Cloud Next '19)](https://i.ytimg.com/vi/fI-5LkBDap8/default.jpg)
![Google Cloud Translate API with DotNet | Google Cloud Translate API | Google.Cloud.Translation.V2](https://i.ytimg.com/vi/3WVFwID1dv8/default.jpg)
![How to easily Continuous Deployment with Cloud Run](https://i.ytimg.com/vi/GhSAQ19f4HA/default.jpg)