Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Cluster Setup
- Apply Network security policies to limit cluster-level access.
- Utilize the CIS benchmark to audit the security configuration of Kubernetes components (etcd, kubelet, kubedns, kubeapi).
- Configure Ingress objects with appropriate security controls.
- Safeguard node metadata and endpoints.
- Reduce reliance on and access to GUI elements.
- Validate platform binaries prior to deployment.
Cluster Hardening
- Limit access to the Kubernetes API.
- Leverage Role-Based Access Controls (RBAC) to reduce exposure.
- Exercise caution with service accounts, such as disabling defaults and minimizing permissions on new ones.
- Maintain frequent Kubernetes updates.
System Hardening
- Reduce the host OS footprint to minimize the attack surface.
- Streamline IAM roles.
- Limit external network access.
- Effectively employ kernel hardening tools like AppArmor and seccomp.
Minimizing Microservice Vulnerabilities
- Establish appropriate OS-level security domains using PSP, OPA, or security contexts.
- Implement robust management for Kubernetes secrets.
- Deploy container runtime sandboxes in multi-tenant setups (e.g., gvisor, kata containers).
- Enforce pod-to-pod encryption using mTLS.
Supply Chain Security
- Reduce the size of base images.
- Secure the supply chain by whitelisting image registries, signing, and validating images.
- Perform static analysis on user workloads (e.g., Kubernetes resources, Dockerfiles).
- Scan images for known vulnerabilities.
Monitoring, Logging, and Runtime Security
- Analyze syscall processes and file activities at the host and container levels to identify malicious behavior.
- Detect threats across physical infrastructure, applications, networks, data, users, and workloads.
- Identify all phases of attacks, regardless of origin or spread.
- Conduct deep analytical investigations to identify bad actors within the environment.
- Guarantee container immutability during runtime.
- Utilize Audit Logs to monitor access patterns.
Requirements
- CKA (Certified Kubernetes Administrator) certification
Target Audience
- Kubernetes practitioners
Testimonials (2)
As i said before , for a person like me (no exp. ) this was a gateway to understanding features and functions with these programs/tools & etc. .
Patrick V. Duylovski - UBB + DZI (KBC GROUP)
Course - Docker and Kubernetes
basic understanding of container/kubernetes and how they interact features of the openshift plattform