EPISODE · Jan 16, 2020 · 33 MIN
Maya Kaczorowski — Container and Orchestration Security
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Containers can improve your security story, but not simply because they are called containers. Maya Kaczorowski, working on container security at Google at the time of this conversation, joins Chris and Robert to separate packaging and orchestration benefits from the isolation guarantees people often assume. She explains how smaller services, consistent environments, and faster updates can help, then considers what an attacker wants from a compromised workload or cluster. The discussion covers image provenance, malicious images, permissions, and alternatives that strengthen isolation, including gVisor and Kata Containers. Maya also describes a practical progression for teams adopting Kubernetes: learn the environment, understand the risks, and build security into deployment decisions rather than treating the first working cluster as a finished system.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Maya Kaczorowski:→ LinkedIn→ Maya's websiteMentioned in this episode:→ Kubernetes→ gVisor→ Kata Containers→ Kubernetes admission controllers→ Exploring container securityFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Introduction01:29 From mathematics to security product work03:42 Moving into container security06:58 Containers and orchestration explained09:12 Docker, runtimes, and orchestration choices10:33 How containers can improve security14:18 Stronger isolation with sandboxed runtimes15:33 Threat modeling an attacker in a container18:03 Where your images come from20:03 Typosquatting and malicious images21:50 Defending workloads and clusters26:26 The container security learning journey31:15 Resources for learning more
Embed this episode
What this episode covers
Containers can improve your security story, but not simply because they are called containers. Maya Kaczorowski, working on container security at Google at the time of this conversation, joins Chris and Robert to separate packaging and orchestration benefits from the isolation guarantees people often assume. She explains how smaller services, consistent environments, and faster updates can help, then considers what an attacker wants from a compromised workload or cluster. The discussion cover...
Ready to play
Maya Kaczorowski — Container and Orchestration Security
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.