Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Cluster Setup
- Leverage network security policies to control cluster-level access
- Utilize the CIS benchmark to audit the security settings of Kubernetes components (etcd, kubelet, kubedns, kubeapi)
- Configure Ingress objects with appropriate security controls
- Safeguard node metadata and endpoints
- Limit the usage of and access to GUI components
- Validate platform binaries prior to deployment
Cluster Hardening
- Limit access to the Kubernetes API
- Apply Role-Based Access Controls (RBAC) to reduce exposure
- Handle service accounts with care, such as disabling defaults and restricting permissions for new accounts
- Keep Kubernetes up to date with frequent updates
System Hardening
- Reduce the host OS footprint to shrink the attack surface
- Streamline IAM roles
- Restrict external network access
- Employ kernel hardening mechanisms like AppArmor and seccomp as appropriate
Minimizing Microservice Vulnerabilities
- Establish OS-level security domains using tools like PSP, OPA, and security contexts
- Manage Kubernetes secrets effectively
- Deploy container runtime sandboxes in multi-tenant setups (e.g., gvisor, kata containers)
- Enforce pod-to-pod encryption via mTLS
Supply Chain Security
- Minimize the size of base images
- Strengthen the supply chain by whitelisting image registries and signing/validating images
- Apply static analysis to user workloads (e.g., Kubernetes resources, Dockerfiles)
- Scan images to identify known vulnerabilities
Monitoring, Logging, and Runtime Security
- Conduct behavioral analysis of system calls and file activities at both host and container levels to spot malicious actions
- Identify threats across physical infrastructure, applications, networks, data, users, and workloads
- Detect attack phases regardless of their origin or spread
- Perform in-depth investigations to identify malicious actors within the environment
- Maintain container immutability during runtime
- Monitor access patterns using Audit Logs
Requirements
- CKA (Certified Kubernetes Administrator) certification
Intended Audience
- Professionals working with Kubernetes
Testimonials (4)
basic understanding of container/kubernetes and how they interact features of the openshift plattform
Eric Scholze - NOW IT GmbH
Course - Introduction to Containers, Kubernetes & OpenShift
About the microservices and how to maintenance kubernetes
Yufri Isnaini Rochmat Maulana - Bank Indonesia
Course - Advanced Platform Engineering: Scaling with Microservices and Kubernetes
How trainer deliver knowledge so effectively
Vu Thoai Le - Reply Polska sp. z o. o.
Course - Certified Kubernetes Administrator (CKA) - exam preparation
The knowledge and exchanges with Augustin