Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Cluster Setup
- Leveraging network security policies to restrict cluster-level access
- Utilizing the CIS benchmark to audit the security configuration of key Kubernetes components, such as etcd, kubelet, kubedns, and kubeapi
- Configuring Ingress objects with robust security controls
- Safeguarding node metadata and endpoints
- Limiting the use of and access to GUI elements
- Validating platform binaries prior to deployment
Cluster Hardening
- Restricting access to the Kubernetes API
- Applying Role-Based Access Controls (RBAC) to minimize security exposure
- Managing service accounts carefully, including disabling defaults and minimizing permissions for newly created accounts
- Maintaining up-to-date Kubernetes versions
System Hardening
- Reducing the host operating system footprint to shrink the attack surface
- Minimizing IAM roles and permissions
- Restricting external network access
- Implementing kernel hardening tools such as AppArmor and seccomp appropriately
Minimizing Microservice Vulnerabilities
- Establishing appropriate OS-level security domains using tools like PSP, OPA, and security contexts
- Effectively managing Kubernetes secrets
- Deploying container runtime sandboxes in multi-tenant environments (e.g., gVisor, kata containers)
- Implementing pod-to-pod encryption using mTLS
Supply Chain Security
- Reducing the footprint of base images
- Securing the supply chain by whitelisting allowed image registries and signing/validating images
- Applying static analysis to user workloads, such as Kubernetes resources and Dockerfiles
- Scanning images for known vulnerabilities
Monitoring, Logging, and Runtime Security
- Conducting behavioral analytics on system calls, processes, and file activities at both host and container levels to identify malicious activity
- Detecting threats across physical infrastructure, applications, networks, data, users, and workloads
- Identifying attack phases regardless of their origin or propagation method
- Performing deep analytical investigations to identify malicious actors within the environment
- Ensuring container immutability during runtime
- Utilizing Audit Logs to monitor access patterns
Requirements
- CKA (Certified Kubernetes Administrator) certification
Target Audience
- Kubernetes practitioners
21 Hours
Testimonials (4)
basic understanding of container/kubernetes and how they interact features of the openshift plattform
Eric Scholze - NOW IT GmbH
Course - Introduction to Containers, Kubernetes & OpenShift
About the microservices and how to maintenance kubernetes
Yufri Isnaini Rochmat Maulana - Bank Indonesia
Course - Advanced Platform Engineering: Scaling with Microservices and Kubernetes
How trainer deliver knowledge so effectively
Vu Thoai Le - Reply Polska sp. z o. o.
Course - Certified Kubernetes Administrator (CKA) - exam preparation
The knowledge and exchanges with Augustin