Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours (3 days)
Course Outline
Cluster Setup
- Implement Network security policies to limit cluster-level access
- Leverage CIS benchmarks to assess the security configuration of Kubernetes components (etcd, kubelet, kubedns, kubeapi)
- Configure Ingress objects with appropriate security controls
- Secure node metadata and endpoints
- Limit the usage of, and access to, GUI elements
- Validate platform binaries prior to deployment
Cluster Hardening
- Restrict access to the Kubernetes API
- Apply Role Based Access Controls to minimize exposure
- Exercise caution with service accounts, such as disabling defaults and minimizing permissions on new accounts
- Keep Kubernetes up to date with frequent updates
System Hardening
- Reduce the host OS footprint to minimize the attack surface
- Limit IAM roles to essential functions only
- Restrict external access to the network
- Utilize kernel hardening tools like AppArmor and seccomp appropriately
Minimizing Microservice Vulnerabilities
- Establish appropriate OS-level security domains, for example using PSP, OPA, and security contexts
- Manage Kubernetes secrets effectively
- Employ container runtime sandboxes in multi-tenant environments (e.g., gvisor, kata containers)
- Enforce pod-to-pod encryption via mTLS
Supply Chain Security
- Reduce the size of base images
- Secure the supply chain by whitelisting allowed image registries and signing and validating images
- Apply static analysis to user workloads, including kubernetes resources and docker files
- Perform vulnerability scans on images for known issues
Monitoring, Logging, and Runtime Security
- Conduct behavioral analytics on syscall processes and file activities at both the host and container levels to identify malicious behavior
- Identify threats across physical infrastructure, applications, networks, data, users, and workloads
- Detect all phases of an attack, regardless of origin or propagation method
- Carry out in-depth analytical investigations to identify malicious actors within the environment
- Guarantee container immutability during runtime
- Utilize Audit Logs to oversee access activities
Requirements
- CKA (Certified Kubernates Administrator) certification
Target Audience
- Professionals working with Kubernetes
Testimonials (4)
basic understanding of container/kubernetes and how they interact features of the openshift plattform
Eric Scholze - NOW IT GmbH
Course - Introduction to Containers, Kubernetes & OpenShift
About the microservices and how to maintenance kubernetes
Yufri Isnaini Rochmat Maulana - Bank Indonesia
Course - Advanced Platform Engineering: Scaling with Microservices and Kubernetes
How trainer deliver knowledge so effectively
Vu Thoai Le - Reply Polska sp. z o. o.
Course - Certified Kubernetes Administrator (CKA) - exam preparation
The knowledge and exchanges with Augustin