課程目錄:Certified Kubernetes Security Specialist (CKS)培訓
4401 人關注
(78637/99817)
課程大綱:

   Certified Kubernetes Security Specialist (CKS)培訓

 

 

 

Introduction

Cluster Setup

Use Network security policies to restrict cluster level access
Use CIS benchmark to review the security configuration of Kubernetes components (etcd, kubelet, kubedns, kubeapi)
Properly set up Ingress objects with security control
Protect node metadata and endpoints
Minimize use of, and access to, GUI elements
Verify platform binaries before deploying
Cluster Hardening

Restrict access to Kubernetes API
Use Role Based Access Controls to minimize exposure
Exercise caution in using service accounts e.g. disable defaults, minimize permissions on newly created ones
Update Kubernetes frequently
System Hardening

Minimize host OS footprint (reduce attack surface)
Minimize IAM roles
Minimize external access to the network
Appropriately use kernel hardening tools such as AppArmor, seccomp
Minimize Microservice Vulnerabilities

Setup appropriate OS level security domains e.g. using PSP, OPA, security contexts
Manage kubernetes secrets
Use container runtime sandboxes in multi-tenant environments (e.g. gvisor, kata containers)
Implement pod to pod encryption by use of mTLS
Supply Chain Security

Minimize base image footprint
Secure your supply chain: whitelist allowed image registries, sign and validate images
Use static analysis of user workloads (e.g. kubernetes resources, docker files)
Scan images for known vulnerabilities
Monitoring, Logging and Runtime Security

Perform behavioral analytics of syscall process and file activities at the host and container level to detect malicious activities
Detect threats within physical infrastructure, apps, networks, data, users and workloads
Detect all phases of attack regardless where it occurs and how it spreads
Perform deep analytical investigation and identification of bad actors within environment
Ensure immutability of containers at runtime
Use Audit Logs to monitor access
Summary and Conclusion


主站蜘蛛池模板: 国产色综合久久无码有码| 狠狠色狠狠色综合日日五| 亚洲综合图片区| 狠狠综合久久AV一区二区三区| 色久综合网精品一区二区| 婷婷综合缴情亚洲狠狠尤物| 国产成人综合精品一区| 色综合久久精品中文字幕首页 | 亚洲综合另类小说色区| 激情综合色五月六月婷婷| 亚洲综合伊人久久大杳蕉| 色欲久久久天天天综合网| 亚洲国产欧美国产综合久久| 香蕉蕉亚亚洲aav综合| 自拍 偷拍 另类 综合图片| 久久综合视频网站| 色欲综合久久中文字幕网| 色综合色综合色综合| 狠狠色丁香婷婷久久综合| 亚洲色婷婷综合久久| 精品福利一区二区三区精品国产第一国产综合精品 | 综合五月激情五月开心婷婷| 日韩欧美在线综合网另类| 伊人色综合久久天天| 精品综合久久久久久97超人| 色天使久久综合网天天| 国产色综合天天综合网 | 亚洲欧美日韩综合一区| 亚洲人成综合网站7777香蕉| 欧美亚洲另类久久综合婷婷| 亚洲综合无码一区二区| 亚洲欧洲国产成人综合在线观看 | 人人狠狠综合久久亚洲婷婷| 久久久久久久综合日本亚洲| 亚洲成a人v欧美综合天堂下载 | 91精品国产综合久久香蕉 | 亚洲狠狠成人综合网| 国产综合精品一区二区三区| 亚洲欧美日韩综合| 久久亚洲综合色一区二区三区 | 色综合天天综合网国产国产人|