Загрузка страницы

Don’t be a fail whale, secure your containers - Sarah Young (Versent)

In the talk, Sarah will look at the different layers of security that can be applied to a container ecosystem and the different team's responsibility in the ecosystem to deliver security. From the sysadmin's point of view, how do I make sure the container orchestrator is secured, what official hardening guides are out there to follow. From an application developers point of view, how does secomp/appapparmor work? To make sure that only the process from the application has access to the host machine. Now that we have the local container secured, how do we make sure our deployments follow the same structure and security profiles. Lastly with our developer's hat on we will look at least privileged or zero test API calls with Istio. Can we add security checks to our container CD pipeline like we would quality gates? Lastly, we will look at this from the point of the security team. How can they have input to all the steps we have taken from the beginning of the process and not the end, and how can we use our security teams’ skills to enhance the security posture of the container ecosystem e.g. with threat modelling. Allowing all the teams to work together breaking down silos to deliver a secure solution.

Sarah is a security architect currently based in Melbourne, Australia. She has previously worked in New Zealand, the UK and Europe across a range of industry sectors. Sarah comes from an infrastructure engineering background and deployed enterprise-grade WAN, LAN and VoIP solutions before moving into the security space and providing independent security consulting to a range of businesses and organisations. In her current role at Versent, Sarah helps enterprises move into the cloud securely, design their secure pipeline and adopt automated security processes.

http://container.camp/
@containercamp

Видео Don’t be a fail whale, secure your containers - Sarah Young (Versent) канала Container Camp
Показать
Комментарии отсутствуют
Введите заголовок:

Введите адрес ссылки:

Введите адрес видео с YouTube:

Зарегистрируйтесь или войдите с
Информация о видео
20 апреля 2020 г. 12:16:00
00:23:50
Другие видео канала
Container Standards and Interfaces: An Update - Brandon PhilipsContainer Standards and Interfaces: An Update - Brandon PhilipsPragmatic Pod Patterns: Leveraging sidecar containers in Kubernetes - James Relph (Capgemini)Pragmatic Pod Patterns: Leveraging sidecar containers in Kubernetes - James Relph (Capgemini)Kubernetes and the Next Generation Data Center - James BuckettKubernetes and the Next Generation Data Center - James BuckettAndrew Martin: Continuous Deployment with DockerAndrew Martin: Continuous Deployment with DockerLessons from running potentially malicious code inside containers - Ben HallLessons from running potentially malicious code inside containers - Ben Hallkubecfg: express the patterns in your declarative Kubernetes config - Angus Lees (Bitnami)kubecfg: express the patterns in your declarative Kubernetes config - Angus Lees (Bitnami)Lessons from Production Incidents at Monzo Bank - Oliver Beattie (Monzo)Lessons from Production Incidents at Monzo Bank - Oliver Beattie (Monzo)Simon Thulbourn: Docker containers for testing and previewing BBC NewsSimon Thulbourn: Docker containers for testing and previewing BBC NewsLessons learnt while operating multi-tenant kubernetes cluster in production - Prateek Nayak (MYOB)Lessons learnt while operating multi-tenant kubernetes cluster in production - Prateek Nayak (MYOB)Aanand Prasad: Development Environments with FigAanand Prasad: Development Environments with FigSet up and manage multi-cloud clusters using the Cluster API - Karan Goel (Google)Set up and manage multi-cloud clusters using the Cluster API - Karan Goel (Google)libp2p and the cloud - Adrian Lanzafame (Protocol Labs)libp2p and the cloud - Adrian Lanzafame (Protocol Labs)Constructive destructiveness for containers - Michael Hausenblas (Mesosphere)Constructive destructiveness for containers - Michael Hausenblas (Mesosphere)Luke Bond: Paz: Continuous Deployment Production Environments Built on CoreOS & DockerLuke Bond: Paz: Continuous Deployment Production Environments Built on CoreOS & DockerMixing cgroupfs v1 & cgroupfs v2: finding solutions for container runtimes - Christian BraunerMixing cgroupfs v1 & cgroupfs v2: finding solutions for container runtimes - Christian BraunerDistributed Command Execution using Containers and Cog -  Vincent De Smet (honestbee)Distributed Command Execution using Containers and Cog - Vincent De Smet (honestbee)Chaos Testing for Docker Containers - Alexei Ledenev (Codefresh)Chaos Testing for Docker Containers - Alexei Ledenev (Codefresh)Consuming cloud services with the Kubernetes Service Catalog - Neil Peterson (Microsoft)Consuming cloud services with the Kubernetes Service Catalog - Neil Peterson (Microsoft)Filesystem mounts in user namespaces - Christian BraunerFilesystem mounts in user namespaces - Christian BraunerBuilding geographically distributed microservices with containers - Jussi Nummelin (Kontena Inc.)Building geographically distributed microservices with containers - Jussi Nummelin (Kontena Inc.)Container Images Considered Harmful  - Aleksa Sarai (SUSE)Container Images Considered Harmful - Aleksa Sarai (SUSE)
Яндекс.Метрика