Get in Touch
 Duration 21 hours (3 days)

Course Outline

Cluster Setup

  • Implement Network security policies to limit cluster-level access
  • Leverage the CIS benchmark to audit the security configurations of Kubernetes components (etcd, kubelet, kubedns, kubeapi)
  • Configure Ingress objects with robust security controls
  • Safeguard node metadata and endpoints
  • Reduce reliance on and access to GUI elements
  • Validate platform binaries prior to deployment

Cluster Hardening

  • Limit access to the Kubernetes API
  • Apply Role Based Access Controls to reduce exposure
  • Manage service accounts with caution, such as disabling defaults and restricting permissions on new accounts
  • Keep Kubernetes updated regularly

System Hardening

  • Reduce the host OS footprint to minimize the attack surface
  • Limit IAM roles
  • Restrict external network access
  • Utilize kernel hardening tools effectively, such as AppArmor and seccomp

Minimize Microservice Vulnerabilities

  • Establish appropriate OS-level security domains using tools like PSP, OPA, and security contexts
  • Manage Kubernetes secrets securely
  • Employ container runtime sandboxes in multi-tenant settings (e.g., gvisor, kata containers)
  • Enable pod-to-pod encryption via mTLS

Supply Chain Security

  • Optimize base image size
  • Secure the supply chain by whitelisting authorized image registries, and signing and validating images
  • Conduct static analysis on user workloads (e.g., Kubernetes resources, docker files)
  • Scan images for known vulnerabilities

Monitoring, Logging and Runtime Security

  • Analyze syscall processes and file activities at both host and container levels to identify malicious behavior
  • Detect threats across physical infrastructure, applications, networks, data, users, and workloads
  • Identify attack phases regardless of their origin or propagation method
  • Conduct in-depth investigations to identify malicious actors within the environment
  • Guarantee container immutability during runtime
  • Utilize Audit Logs for access monitoring

Requirements

  • CKA (Certified Kubernetes Administrator) certification

Target Audience

  • Kubernetes practitioners

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories