Maya Kaczorowski — Container and Orchestration Security episode artwork

EPISODE · Jan 16, 2020 · 33 MIN

Maya Kaczorowski — Container and Orchestration Security

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Containers can improve your security story, but not simply because they are called containers. Maya Kaczorowski, working on container security at Google at the time of this conversation, joins Chris and Robert to separate packaging and orchestration benefits from the isolation guarantees people often assume. She explains how smaller services, consistent environments, and faster updates can help, then considers what an attacker wants from a compromised workload or cluster. The discussion covers image provenance, malicious images, permissions, and alternatives that strengthen isolation, including gVisor and Kata Containers. Maya also describes a practical progression for teams adopting Kubernetes: learn the environment, understand the risks, and build security into deployment decisions rather than treating the first working cluster as a finished system.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Maya Kaczorowski:→ LinkedIn→ Maya's websiteMentioned in this episode:→ Kubernetes→ gVisor→ Kata Containers→ Kubernetes admission controllers→ Exploring container securityFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Introduction01:29 From mathematics to security product work03:42 Moving into container security06:58 Containers and orchestration explained09:12 Docker, runtimes, and orchestration choices10:33 How containers can improve security14:18 Stronger isolation with sandboxed runtimes15:33 Threat modeling an attacker in a container18:03 Where your images come from20:03 Typosquatting and malicious images21:50 Defending workloads and clusters26:26 The container security learning journey31:15 Resources for learning more

Episode metadata supplied by the publisher feed · Published Jan 16, 2020

Embed this episode

Containers can improve your security story, but not simply because they are called containers. Maya Kaczorowski, working on container security at Google at the time of this conversation, joins Chris and Robert to separate packaging and orchestration benefits from the isolation guarantees people often assume. She explains how smaller services, consistent environments, and faster updates can help, then considers what an attacker wants from a compromised workload or cluster. The discussion cover...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Maya Kaczorowski — Container and Orchestration Security

0:00 33:31

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 33 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on January 16, 2020.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!