課程目錄:Certified Kubernetes Security Specialist (CKS)培訓
4401 人關注
(78637/99817)
課程大綱:

   Certified Kubernetes Security Specialist (CKS)培訓

 

 

 

Introduction

Cluster Setup

Use Network security policies to restrict cluster level access
Use CIS benchmark to review the security configuration of Kubernetes components (etcd, kubelet, kubedns, kubeapi)
Properly set up Ingress objects with security control
Protect node metadata and endpoints
Minimize use of, and access to, GUI elements
Verify platform binaries before deploying
Cluster Hardening

Restrict access to Kubernetes API
Use Role Based Access Controls to minimize exposure
Exercise caution in using service accounts e.g. disable defaults, minimize permissions on newly created ones
Update Kubernetes frequently
System Hardening

Minimize host OS footprint (reduce attack surface)
Minimize IAM roles
Minimize external access to the network
Appropriately use kernel hardening tools such as AppArmor, seccomp
Minimize Microservice Vulnerabilities

Setup appropriate OS level security domains e.g. using PSP, OPA, security contexts
Manage kubernetes secrets
Use container runtime sandboxes in multi-tenant environments (e.g. gvisor, kata containers)
Implement pod to pod encryption by use of mTLS
Supply Chain Security

Minimize base image footprint
Secure your supply chain: whitelist allowed image registries, sign and validate images
Use static analysis of user workloads (e.g. kubernetes resources, docker files)
Scan images for known vulnerabilities
Monitoring, Logging and Runtime Security

Perform behavioral analytics of syscall process and file activities at the host and container level to detect malicious activities
Detect threats within physical infrastructure, apps, networks, data, users and workloads
Detect all phases of attack regardless where it occurs and how it spreads
Perform deep analytical investigation and identification of bad actors within environment
Ensure immutability of containers at runtime
Use Audit Logs to monitor access
Summary and Conclusion


精品国产高清自在线一区二区三区| 99精品视频在线观看re| 久久九九AV免费精品| 国产精品不卡在线| 91国语精品自产拍在线观看一| 国产精品毛片无码| 日韩精品专区在线影院重磅| 日本午夜精品一区二区三区电影| 国产乱人伦偷精品视频不卡| 久久久国产精品va麻豆| 日韩精品一区二区亚洲AV观看| 精品视频在线观看你懂的一区 | 久久精品视频国产| 亚洲七七久久精品中文国产| 午夜麻豆国产精品无码| 久久99久久99精品免视看动漫| 少妇人妻偷人精品一区二区 | 国产亚洲高清在线精品不卡| 亚洲av专区无码观看精品天堂| 精品福利资源在线| 精品久久国产一区二区三区香蕉| 日韩加勒比一本无码精品| 国产香蕉久久精品综合网| 精品无码久久久久久尤物| 久久免费精品一区二区| 精品人妻无码专区中文字幕| 青青久久精品国产免费看| 国产精品视频永久免费播放| 国产精品成人在线| 亚洲国产精品久久网午夜| 久热综合在线亚洲精品| 亚洲日韩国产精品第一页一区| 亚洲精品视频免费观看| 国产真实乱子伦精品视| 国产精品成久久久久三级| 伊人无码精品久久一区二区| 国产精品久久亚洲不卡动漫| 69p69国产精品| 亚洲精品无码久久毛片波多野吉衣 | 亚洲中文字幕久久精品无码A| 国产精品亚洲片在线va|