Get in Touch
 Duration 21 hours (3 days)

Course Outline

Cluster Setup

  • Implement Network security policies to limit cluster-level access
  • Leverage CIS benchmarks to assess the security configuration of Kubernetes components (etcd, kubelet, kubedns, kubeapi)
  • Configure Ingress objects with appropriate security controls
  • Secure node metadata and endpoints
  • Limit the usage of, and access to, GUI elements
  • Validate platform binaries prior to deployment

Cluster Hardening

  • Restrict access to the Kubernetes API
  • Apply Role Based Access Controls to minimize exposure
  • Exercise caution with service accounts, such as disabling defaults and minimizing permissions on new accounts
  • Keep Kubernetes up to date with frequent updates

System Hardening

  • Reduce the host OS footprint to minimize the attack surface
  • Limit IAM roles to essential functions only
  • Restrict external access to the network
  • Utilize kernel hardening tools like AppArmor and seccomp appropriately

Minimizing Microservice Vulnerabilities

  • Establish appropriate OS-level security domains, for example using PSP, OPA, and security contexts
  • Manage Kubernetes secrets effectively
  • Employ container runtime sandboxes in multi-tenant environments (e.g., gvisor, kata containers)
  • Enforce pod-to-pod encryption via mTLS

Supply Chain Security

  • Reduce the size of base images
  • Secure the supply chain by whitelisting allowed image registries and signing and validating images
  • Apply static analysis to user workloads, including kubernetes resources and docker files
  • Perform vulnerability scans on images for known issues

Monitoring, Logging, and Runtime Security

  • Conduct behavioral analytics on syscall processes and file activities at both the host and container levels to identify malicious behavior
  • Identify threats across physical infrastructure, applications, networks, data, users, and workloads
  • Detect all phases of an attack, regardless of origin or propagation method
  • Carry out in-depth analytical investigations to identify malicious actors within the environment
  • Guarantee container immutability during runtime
  • Utilize Audit Logs to oversee access activities

Requirements

  • CKA (Certified Kubernates Administrator) certification

Target Audience

  • Professionals working with Kubernetes

Number of participants


Price per participant

Testimonials (4)

Upcoming Courses

Related Categories