Skip to Content
容器安全
book

容器安全

by Liz Rice
May 2025
Beginner to intermediate
200 pages
2h 20m
Chinese
O'Reilly Media, Inc.
Content preview from 容器安全

结论

恭喜您完成了这本书!

在这一点上,我首先希望你现在对容器有一个坚实的心理模型。在讨论如何确保容器部署的安全时,这将对您大有裨益。如果普通容器无法在工作负载之间提供足够的隔离,您还应该了解不同的隔离选项。

我还希望你现在已经充分了解了容器之间以及容器与外部世界之间的通信方式。Network+ 本身就是一个庞大的话题,但这里最重要的启示是,容器给你提供的不仅是一个部署单元,还有一个安全单元。有很多限制流量的选项,只有符合要求的流量才能在容器之间流动,并与外部世界进行通信。

我想你已经明白了分层防御在发生漏洞时的作用。如果攻击者利用了你部署中的漏洞,还有其他墙壁他们可能无法攻破。防御层越多,攻击成功的可能性就越小。

正如您在第 14 章中看到的,有一些容器特有的预防措施,您可以使用它们来抵御针对网络应用程序的最常见攻击。前十名并不能涵盖部署中可能存在的所有弱点。既然本书已经接近尾声,你可能需要回顾一下"容器威胁模型 "中容器特有的攻击载体列表您还可以在附录中找到问题列表,帮助您评估部署中哪些地方可能最容易受到攻击,哪些地方应该加强防御。

我希望本书中的信息能帮助你保卫你的部署,无论发生什么。如果你遭受了攻击--无论你是被攻破了还是成功地保护了你的应用程序和数据的安全--我都很想听听你的看法。我们随时欢迎关于攻击的反馈、评论和故事,你可以在containersecurity.tech 上提出问题。我是 Twitter 上的 @lizrice

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

《敏捷开发艺术》第二版

《敏捷开发艺术》第二版

James Shore, Shane Warden
AI工程

AI工程

Chip Huyen
算法精讲视频课程:24篇系列讲座

算法精讲视频课程:24篇系列讲座

罗伯特·塞奇威克, 凯文·韦恩(Kevin Wayne)
计算机视觉中的实用机器学习

计算机视觉中的实用机器学习

Valliappa Lakshmanan, Martin Görner, Ryan Gillard

Publisher Resources

ISBN: 9798341658448