Talk
Intermediate

Hacking & Securing Kubernetes

Rejected

Session Description

The talk will be around the open source project kube-goat ("Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground - https://github.com/madhuakula/kubernetes-goat).


I will be demoing a few attack vectors and then later showing how other open source projects can protect your kubernetes workloads e.g

Find deprecated resources

Pluto - A cli tool to help discover deprecated apiVersions in Kubernetes

(https://github.com/FairwindsOps/pluto)

Find vulnerabilities & misconfigurations

Krane - Kubernetes RBAC static analysis & visualisation tool

(https://github.com/appvia/krane)

Trivy - Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

(https://github.com/aquasecurity/trivy)


I will also be covering the basic theory of

  1. OWASP top 10 for kubernetes (https://owasp.org/www-project-kubernetes-top-ten/),
  2. NSA & CISA Guidelines (https://research.nccgroup.com/2021/09/09/nsa-cisa-kubernetes-security-guidance-a-critical-review/),
  3. CIS Benchmark (https://www.cisecurity.org/benchmark/kubernetes), 

Key Takeaways

None

References

Session Categories

FOSS

Speakers

Sumir Broota
Research Developer IDfy
Sumir Broota

Reviews

0 %
Approvability
0
Approvals
1
Rejections
1
Not Sure
More suitable for KubeCon, I guess.
Reviewer #1
Rejected
Not too sure about this one
Reviewer #2
Not Sure