Тёмный

Run As “Root”, Not Root: User Namespaces In K8s- Marga Manterola, Isovalent & Rodrigo Campos Catelin 

CNCF [Cloud Native Computing Foundation]
Подписаться 119 тыс.
Просмотров 677
50% 1

Don’t miss out! Join us at our upcoming event: KubeCon + CloudNativeCon Europe in Amsterdam, The Netherlands from April 17-21, 2023. Learn more at kubecon.io The conference features presentations from developers and end users of Kubernetes, Prometheus, Envoy, and all of the other CNCF-hosted projects.
Run As “Root”, Not Root: User Namespaces In K8s - Marga Manterola, Isovalent & Rodrigo Campos Catelin, Microsoft
Speakers: Rodrigo Campos Catelin, Marga Manterola
What if I told you that there's a bool you can set in your pod yaml that mitigates many CVEs out there? Not just any CVEs, but some HIGH and CRITICAL ones! This feature is coming to Kubernetes, thanks to user namespaces, and we'll tell you all about it.
User namespaces is a kernel feature that isolates the user in the container from the one in the host. A process running as root in a container can run as a different (non-root) user in the host. This is a HUGE improvement: if a process escapes the container, the privileges on the host are significantly reduced. Furthermore, some capabilities are void and others are only valid inside the user namespace.
Many container workloads that run as root today can benefit from this already: enable user namespace in their pod yaml and be more secure without additional changes.
This talk will explain how to use this feature in your cluster, how it is implemented, the current state of the KEP and future work and challenges in this area.

Опубликовано:

 

28 сен 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 1   
@autohmae
@autohmae 9 месяцев назад
The stateful support of this is came in Kubernetes 1.28 as Alpha.
Далее
Китайка и Максим Крипер😂😆
00:21
FATAL CHASE 😳 😳
00:19
Просмотров 709 тыс.
User Namespaces Part 1, Phil Estes
11:34
Просмотров 10 тыс.
Learn How to Solve Kubernetes Issues in SECONDS!
17:46
Build your own Container Runtime
37:37
Просмотров 9 тыс.
How Docker Works - Intro to Namespaces
12:56
Просмотров 168 тыс.