Get in Touch
 Duration 21 hours

Course Outline

Cluster Setup

  • Leverage network security policies to control cluster-level access
  • Utilize the CIS benchmark to audit the security settings of Kubernetes components (etcd, kubelet, kubedns, kubeapi)
  • Configure Ingress objects with appropriate security controls
  • Safeguard node metadata and endpoints
  • Limit the usage of and access to GUI components
  • Validate platform binaries prior to deployment

Cluster Hardening

  • Limit access to the Kubernetes API
  • Apply Role-Based Access Controls (RBAC) to reduce exposure
  • Handle service accounts with care, such as disabling defaults and restricting permissions for new accounts
  • Keep Kubernetes up to date with frequent updates

System Hardening

  • Reduce the host OS footprint to shrink the attack surface
  • Streamline IAM roles
  • Restrict external network access
  • Employ kernel hardening mechanisms like AppArmor and seccomp as appropriate

Minimizing Microservice Vulnerabilities

  • Establish OS-level security domains using tools like PSP, OPA, and security contexts
  • Manage Kubernetes secrets effectively
  • Deploy container runtime sandboxes in multi-tenant setups (e.g., gvisor, kata containers)
  • Enforce pod-to-pod encryption via mTLS

Supply Chain Security

  • Minimize the size of base images
  • Strengthen the supply chain by whitelisting image registries and signing/validating images
  • Apply static analysis to user workloads (e.g., Kubernetes resources, Dockerfiles)
  • Scan images to identify known vulnerabilities

Monitoring, Logging, and Runtime Security

  • Conduct behavioral analysis of system calls and file activities at both host and container levels to spot malicious actions
  • Identify threats across physical infrastructure, applications, networks, data, users, and workloads
  • Detect attack phases regardless of their origin or spread
  • Perform in-depth investigations to identify malicious actors within the environment
  • Maintain container immutability during runtime
  • Monitor access patterns using Audit Logs

Requirements

  • CKA (Certified Kubernetes Administrator) certification

Intended Audience

  • Professionals working with Kubernetes

Number of participants


Price per participant

Testimonials (4)

Upcoming Courses

Related Categories