Omer Levi Hevroni — K8s can keep a secret? episode artwork

EPISODE · May 1, 2019 · 36 MIN

Omer Levi Hevroni — K8s can keep a secret?

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Putting an application in Kubernetes does not solve the problem of getting secrets to it safely. Omer Levi Hevroni, a developer and security champion, explains the risks that led his team to create Kamus. He starts with Kubernetes basics and the broader responsibilities of developers who own applications through deployment and operation. The discussion then follows secrets from source control into the cluster, comparing native mechanisms with encryption and external key-management options. Omer walks through the Kamus workflow, including how an encrypted secret is tied to the application allowed to decrypt it. He also discusses the threats the design addresses and the value of documenting assumptions. This archive conversation captures a practical approach to secrets management and its tradeoffs.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Omer Levi Hevroni:→ Omer Levi Hevroni on GitHubMentioned in this episode:→ Kamus — historical project repository→ Kubernetes→ Azure Key VaultFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Can Kubernetes keep a secret?02:38 From developer to security champion04:16 Learning to code and owning applications06:32 Kubernetes basics08:44 The challenge of handling application secrets10:34 Developers responsible for the whole lifecycle11:19 Keeping secrets usable and controlled14:18 Secrets accidentally committed to source code17:09 Options for secrets in Kubernetes18:58 Recovery and consuming secrets in application code21:08 Encryption and external key management24:22 Why the team built Kamus26:42 The Kamus encryption and decryption workflow28:21 Where encrypted secrets and keys live31:43 Threats addressed by the design34:22 Documentation, threat model, and further resources

Episode metadata supplied by the publisher feed · Published May 1, 2019

Embed this episode

Putting an application in Kubernetes does not solve the problem of getting secrets to it safely. Omer Levi Hevroni, a developer and security champion, explains the risks that led his team to create Kamus. He starts with Kubernetes basics and the broader responsibilities of developers who own applications through deployment and operation. The discussion then follows secrets from source control into the cluster, comparing native mechanisms with encryption and external key-management options. Om...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Omer Levi Hevroni — K8s can keep a secret?

0:00 36:42

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 36 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on May 1, 2019.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!