Skip to Content
Kubernetes in Action
book

Kubernetes in Action

by Marko Luksa
January 2018
Beginner to intermediate
624 pages
19h 23m
English
Manning Publications
Content preview from Kubernetes in Action

Chapter 13. Securing cluster nodes and the network

This chapter covers

  • Using the node’s default Linux namespaces in pods
  • Running containers as different users
  • Running privileged containers
  • Adding or dropping a container’s kernel capabilities
  • Defining security policies to limit what pods can do
  • Securing the pod network

In the previous chapter, we talked about securing the API server. If an attacker gets access to the API server, they can run whatever they like by packaging their code into a container image and running it in a pod. But can they do any real damage? Aren’t containers isolated from other containers and from the node they’re running on?

Not necessarily. In this chapter, you’ll learn how to allow pods to access the resources of the ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Kubernetes: Up and Running, 2nd Edition

Kubernetes: Up and Running, 2nd Edition

Brendan Burns, Joe Beda, Kelsey Hightower
Terraform in Action

Terraform in Action

Scott Winkler
Kubernetes for Beginners

Kubernetes for Beginners

Bogdan Stashchuk

Publisher Resources

ISBN: 9781617293726Supplemental ContentPublisher SupportOtherPublisher WebsiteSupplemental ContentErrata PagePurchase Link