Brian Andrzejewski -- Containers Again episode artwork

EPISODE · Oct 24, 2017 · 29 MIN

Brian Andrzejewski -- Containers Again

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Containers make deployment repeatable, but insecure images, excessive privileges, and unmanaged secrets can travel with them. Brian Andrzejewski shares lessons from introducing containers in a government environment and developing a more deliberate security approach. He explains why early choices such as SSH access need reconsideration, how orchestration changes operations, and why teams need policies for the images they trust. Chris and Robert explore running without unnecessary privileges, read-only filesystems, vulnerability checks, and the difference between protecting the container infrastructure and the application inside it. Brian also discusses secrets, maturity models, and the role of benchmarks and guidance. The conversation offers a practical progression from experimenting with Docker to operating containers with consistent controls, visible dependencies, and a plan for ongoing maintenance.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Brian Andrzejewski:→ Brian Andrzejewski on LinkedInMentioned in this episode:→ Docker→ Docker Hub→ CIS Docker Benchmark→ NIST SP 800-190 — Application Container Security GuideFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Container security with Brian Andrzejewski00:46 Brian’s security origin story03:33 Introducing containers in a government environment05:33 SSH access and disposable containers06:28 Moving toward orchestration07:47 Policies for trusted container images11:30 Privileges and read-only filesystems12:55 A maturity model for container security16:43 Dependency inventory and CVE checks17:56 Rebuilding and checking running containers19:53 Application security inside containers22:32 Handling secrets23:36 Lessons for teams getting started26:43 Benchmarks and resources

Episode metadata supplied by the publisher feed · Published Oct 24, 2017

Embed this episode

Containers make deployment repeatable, but insecure images, excessive privileges, and unmanaged secrets can travel with them. Brian Andrzejewski shares lessons from introducing containers in a government environment and developing a more deliberate security approach. He explains why early choices such as SSH access need reconsideration, how orchestration changes operations, and why teams need policies for the images they trust. Chris and Robert explore running without unnecessary privileges, ...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Brian Andrzejewski -- Containers Again

0:00 29:31

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 29 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on October 24, 2017.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!