課程目錄:Certified Kubernetes Security Specialist (CKS)培訓
4401 人關注
(78637/99817)
課程大綱:

   Certified Kubernetes Security Specialist (CKS)培訓

 

 

 

Introduction

Cluster Setup

Use Network security policies to restrict cluster level access
Use CIS benchmark to review the security configuration of Kubernetes components (etcd, kubelet, kubedns, kubeapi)
Properly set up Ingress objects with security control
Protect node metadata and endpoints
Minimize use of, and access to, GUI elements
Verify platform binaries before deploying
Cluster Hardening

Restrict access to Kubernetes API
Use Role Based Access Controls to minimize exposure
Exercise caution in using service accounts e.g. disable defaults, minimize permissions on newly created ones
Update Kubernetes frequently
System Hardening

Minimize host OS footprint (reduce attack surface)
Minimize IAM roles
Minimize external access to the network
Appropriately use kernel hardening tools such as AppArmor, seccomp
Minimize Microservice Vulnerabilities

Setup appropriate OS level security domains e.g. using PSP, OPA, security contexts
Manage kubernetes secrets
Use container runtime sandboxes in multi-tenant environments (e.g. gvisor, kata containers)
Implement pod to pod encryption by use of mTLS
Supply Chain Security

Minimize base image footprint
Secure your supply chain: whitelist allowed image registries, sign and validate images
Use static analysis of user workloads (e.g. kubernetes resources, docker files)
Scan images for known vulnerabilities
Monitoring, Logging and Runtime Security

Perform behavioral analytics of syscall process and file activities at the host and container level to detect malicious activities
Detect threats within physical infrastructure, apps, networks, data, users and workloads
Detect all phases of attack regardless where it occurs and how it spreads
Perform deep analytical investigation and identification of bad actors within environment
Ensure immutability of containers at runtime
Use Audit Logs to monitor access
Summary and Conclusion


主站蜘蛛池模板: 五月天激激婷婷大综合丁香| 久久93精品国产91久久综合| 国产综合成人色产三级高清在线精品发布| 久久婷婷是五月综合色狠狠| 天天看天天摸色天天综合网| 成人久久综合网| 国产激情综合在线观看| 欧美日韩亚洲综合在线| 亚洲精品综合一二三区在线| 中文字幕亚洲综合小综合在线| 一本久久a久久精品综合夜夜| 激情五月激情综合网| 五月激情综合网| 伊人成色综合网| 久久综合九色综合精品| 亚洲国产精品综合久久一线| 色综合天天综合网国产成人网| 婷婷久久综合九色综合98| 亚洲国产欧美国产综合久久| 久久亚洲高清综合| 久久香综合精品久久伊人| 精品综合久久久久久97| 99精品国产综合久久久久五月天| 狠狠色丁香婷婷久久综合| 亚洲国产美国国产综合一区二区| 狠狠色噜噜狠狠狠狠色综合久AV| 97久久婷婷五月综合色d啪蜜芽| 狠狠色狠狠色综合日日五| 亚洲va欧美va国产综合| 亚洲欧洲国产成人综合在线观看| 久久久久AV综合网成人| 亚洲 欧美 综合 高清 在线| 久久婷婷五月综合色99啪ak| 日韩欧美国产综合| 久久亚洲欧洲国产综合| 开心五月激情综合婷婷| 亚洲国产综合人成综合网站| 综合激情五月综合激情五月激情1| 亚洲精品综合一二三区在线| 伊人久久综合热线大杳蕉下载| 97久久婷婷五月综合色d啪蜜芽|