Skip to Content
Kubernetes Security: Attacking and Defending Kubernetes
on-demand course

Kubernetes Security: Attacking and Defending Kubernetes

with Andrew Martin
December 2021
Advanced
2h 45m
English
O'Reilly Media, Inc.
Closed Captioning available in German, English, Spanish, French, Japanese, Korean, Portuguese (Portugal, Brazil), Chinese (Simplified), Chinese (Traditional)

Overview

Like many complex systems Kubernetes has historically been insecure by default, and contains a number of “footguns” that make secure deployments difficult. Segregation of duty, least privilege, and a rigorous Continuous Security approach are the foundations of any secure system—however these become more difficult to achieve in distributed systems with many moving parts.

But all is not lost! With an understanding of the foundational layers and principles including micro-segmentation, zero trust, and local PKI, Kubernetes can be secured against the most ardent of attackers.

The course guides attendees through an introduction to Linux container security, and progresses to advanced Kubernetes cluster security. It emphasizes pragmatic threat modelling and risk assessment based on an understanding of the tools and primitives available.

What you’ll learn and how you can apply it

By the end of this course, you’ll understand:

  • Linux and container security
  • The Kubernetes attack surface
  • Automated container security testing and DevSecOps workflows
  • Open Source security tooling and the vendor landscape

And you’ll be able to:

  • Break out of a container
  • Attack and harden Kubernetes
  • Security test Kubernetes clusters
This course is for you because…
  • You’re an intermediate to advanced Kubernetes user who wants to strengthen their security understanding
  • You want to become an SRE, DevOps, or DevSecOps engineer

Prerequisites

  • Familiarity and comfort with Docker, Kubernetes, and the Linux command line

Recommended preparation:

  • Make sure that you have a Linux VM or physical machine with at least 8GB of RAM and 20GB of disk space, as well as a second machine (or VM) with a Linux terminal. You are welcome to follow along within these, but you will need both Linux machines in order to fully participate in the exercises.
  • Read Kubernetes: Up and Running (book), Chapter 1. Introduction
  • Read Kubernetes Security (report)
  • Chapter 1. Approaching Kubernetes Security
  • Chapter 6. Running Containers Securely

Recommended follow-up:

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Watch now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Kubernetes Security

Kubernetes Security

Liz Rice, Michael Hausenblas

Publisher Resources

ISBN: 0636920668794