Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours (3 days)
Course Outline
Cluster Setup
- Implement Network security policies to limit cluster-level access
- Leverage the CIS benchmark to audit the security configurations of Kubernetes components (etcd, kubelet, kubedns, kubeapi)
- Configure Ingress objects with robust security controls
- Safeguard node metadata and endpoints
- Reduce reliance on and access to GUI elements
- Validate platform binaries prior to deployment
Cluster Hardening
- Limit access to the Kubernetes API
- Apply Role Based Access Controls to reduce exposure
- Manage service accounts with caution, such as disabling defaults and restricting permissions on new accounts
- Keep Kubernetes updated regularly
System Hardening
- Reduce the host OS footprint to minimize the attack surface
- Limit IAM roles
- Restrict external network access
- Utilize kernel hardening tools effectively, such as AppArmor and seccomp
Minimize Microservice Vulnerabilities
- Establish appropriate OS-level security domains using tools like PSP, OPA, and security contexts
- Manage Kubernetes secrets securely
- Employ container runtime sandboxes in multi-tenant settings (e.g., gvisor, kata containers)
- Enable pod-to-pod encryption via mTLS
Supply Chain Security
- Optimize base image size
- Secure the supply chain by whitelisting authorized image registries, and signing and validating images
- Conduct static analysis on user workloads (e.g., Kubernetes resources, docker files)
- Scan images for known vulnerabilities
Monitoring, Logging and Runtime Security
- Analyze syscall processes and file activities at both host and container levels to identify malicious behavior
- Detect threats across physical infrastructure, applications, networks, data, users, and workloads
- Identify attack phases regardless of their origin or propagation method
- Conduct in-depth investigations to identify malicious actors within the environment
- Guarantee container immutability during runtime
- Utilize Audit Logs for access monitoring
Requirements
- CKA (Certified Kubernetes Administrator) certification
Target Audience
- Kubernetes practitioners
Testimonials (1)
his empathy and ability to translate complex concepts into easily understandable cases
Giorgio - Accenture Italia
Course - Certified Kubernetes Security Specialist (CKS)
Machine Translated