EPISODE · Oct 24, 2017 · 29 MIN
Brian Andrzejewski -- Containers Again
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Containers make deployment repeatable, but insecure images, excessive privileges, and unmanaged secrets can travel with them. Brian Andrzejewski shares lessons from introducing containers in a government environment and developing a more deliberate security approach. He explains why early choices such as SSH access need reconsideration, how orchestration changes operations, and why teams need policies for the images they trust. Chris and Robert explore running without unnecessary privileges, read-only filesystems, vulnerability checks, and the difference between protecting the container infrastructure and the application inside it. Brian also discusses secrets, maturity models, and the role of benchmarks and guidance. The conversation offers a practical progression from experimenting with Docker to operating containers with consistent controls, visible dependencies, and a plan for ongoing maintenance.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Brian Andrzejewski:→ Brian Andrzejewski on LinkedInMentioned in this episode:→ Docker→ Docker Hub→ CIS Docker Benchmark→ NIST SP 800-190 — Application Container Security GuideFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Container security with Brian Andrzejewski00:46 Brian’s security origin story03:33 Introducing containers in a government environment05:33 SSH access and disposable containers06:28 Moving toward orchestration07:47 Policies for trusted container images11:30 Privileges and read-only filesystems12:55 A maturity model for container security16:43 Dependency inventory and CVE checks17:56 Rebuilding and checking running containers19:53 Application security inside containers22:32 Handling secrets23:36 Lessons for teams getting started26:43 Benchmarks and resources
Embed this episode
What this episode covers
Containers make deployment repeatable, but insecure images, excessive privileges, and unmanaged secrets can travel with them. Brian Andrzejewski shares lessons from introducing containers in a government environment and developing a more deliberate security approach. He explains why early choices such as SSH access need reconsideration, how orchestration changes operations, and why teams need policies for the images they trust. Chris and Robert explore running without unnecessary privileges, ...
Ready to play
Brian Andrzejewski -- Containers Again
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.