Chapter 9Advanced Architectures and Specialized Domains
Advanced cloud architectures challenge conventional security assumptions, demanding new models of control, visibility, and resilience. As workloads shift from centralized infrastructure to distributed, ephemeral, and service-oriented ecosystems, the attack surface becomes broader, more dynamic, and more challenging to contain. Understanding how to design and secure these modern architectures—whether through container orchestration, serverless computing, or edge deployments—is essential to maintaining control over the trust boundaries, enforcing policy, and ensuring continuity under adverse conditions. Security strategy must adapt not only to the technologies in use, but also to their failure modes and operational unpredictability.
Container Security and Kubernetes Hardening
Containers have become a crucial component of modern cloud-native architecture, providing consistency across environments and accelerating deployment cycles. However, their lightweight and ephemeral nature introduces unique security challenges that require deliberate control measures at every stage of the container lifecycle. A secure container deployment begins with the integrity of the base image. Minimal, purpose-built base images significantly reduce the attack surface by eliminating unnecessary software packages and system tools that could be exploited. Images must be sourced from trusted registries, and their provenance should be verifiable ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access