課程目錄:Certified Kubernetes Security Specialist (CKS)培訓
4401 人關注
(78637/99817)
課程大綱:

   Certified Kubernetes Security Specialist (CKS)培訓

 

 

 

Introduction

Cluster Setup

Use Network security policies to restrict cluster level access
Use CIS benchmark to review the security configuration of Kubernetes components (etcd, kubelet, kubedns, kubeapi)
Properly set up Ingress objects with security control
Protect node metadata and endpoints
Minimize use of, and access to, GUI elements
Verify platform binaries before deploying
Cluster Hardening

Restrict access to Kubernetes API
Use Role Based Access Controls to minimize exposure
Exercise caution in using service accounts e.g. disable defaults, minimize permissions on newly created ones
Update Kubernetes frequently
System Hardening

Minimize host OS footprint (reduce attack surface)
Minimize IAM roles
Minimize external access to the network
Appropriately use kernel hardening tools such as AppArmor, seccomp
Minimize Microservice Vulnerabilities

Setup appropriate OS level security domains e.g. using PSP, OPA, security contexts
Manage kubernetes secrets
Use container runtime sandboxes in multi-tenant environments (e.g. gvisor, kata containers)
Implement pod to pod encryption by use of mTLS
Supply Chain Security

Minimize base image footprint
Secure your supply chain: whitelist allowed image registries, sign and validate images
Use static analysis of user workloads (e.g. kubernetes resources, docker files)
Scan images for known vulnerabilities
Monitoring, Logging and Runtime Security

Perform behavioral analytics of syscall process and file activities at the host and container level to detect malicious activities
Detect threats within physical infrastructure, apps, networks, data, users and workloads
Detect all phases of attack regardless where it occurs and how it spreads
Perform deep analytical investigation and identification of bad actors within environment
Ensure immutability of containers at runtime
Use Audit Logs to monitor access
Summary and Conclusion


主站蜘蛛池模板: 久久婷婷激情综合色综合俺也去| 一本色道久久综合亚洲精品| 国产91色综合久久免费| 亚洲精品第一国产综合境外资源| 久久综合伊人77777| 久久国产综合精品五月天| 亚洲综合伊人久久综合| 国产成人精品综合久久久 | 色婷婷色综合激情国产日韩| 久久久久久综合网天天| 综合三区后入内射国产馆| 亚洲综合精品香蕉久久网| 亚洲综合色视频在线观看| 亚洲欧洲国产成人综合在线观看 | 日韩欧美国产综合| 66精品综合久久久久久久| 国产综合内射日韩久| 久久婷婷五月综合97色一本一本 | HEYZO无码综合国产精品| 国产成人综合洲欧美在线| 精品国产综合区久久久久久| 亚洲国产成人五月综合网| 亚洲综合无码一区二区| 日韩欧美色综合网站| 亚洲国产综合精品中文第一区| 久久综合久久综合亚洲| 涩涩色中文综合亚洲| 亚洲综合色成在线播放| 国产成人综合亚洲AV第一页| 亚洲AV人无码综合在线观看| 国产成人综合美国十次| 日日AV色欲香天天综合网| 情人伊人久久综合亚洲| 欧美日韩国产综合视频一区二区二| 久久久久噜噜噜亚洲熟女综合 | 色天使久久综合网天天| 国产综合色香蕉精品五月婷| 一本久道久久综合狠狠爱| 亚洲欧洲日产国产综合网| 2020国产精品亚洲综合网| 日日AV色欲香天天综合网|