Security: Hosts, Registries, Content and Pipelines episode artwork

EPISODE · Nov 6, 2017 · 41 MIN

Security: Hosts, Registries, Content and Pipelines

from PodCTL - Enterprise Kubernetes · host Brian Gracely & Tyler Britten

Show: 14Show Overview: Brian and Tyler talk address some of the many layers of security required in a container environment. This show will be part of a series on container and Kubernetes security. They look at security requirement in the Container Host, Container Content, Container Registry, and Software Build Processes.   Show Notes and News:10 Layers of Container SecurityGoogle, VMware and Pivotal announced a Hybrid Cloud partnership with KubernetesGoogle and Cisco announced a Hybrid Cloud partnership with Kubernetes (and more)Docker adds support for Kubernetes to DockerEERancher makes Kubernetes the primary orchestratorMicrosoft announces new Azure Container Service, AKSOracle announced Kubernetes on Oracle Linux (and some installers)Heptio announces new toolsTopic 1 - Let’s start at the bottom of the stack with the security needed on a container host.Linux namespaces - isolation Linux capabilities and SECCOMP - restrict routes, ports, limiting process calls SELinux (or AppArmor) - mandatory access controls cGroups - resource managementTopic 2 - Next in the stack, or outside the stack, is the sources of container content.Trusted sources (known registries vs. public registries (e.g. DockerHub) Scanning the content of containers Managing the versions, patches of container contentTopic 3 - Once we have the content (applications), we need a secure place to store and access it - container registries.Making a registry highly-available Who manages and audits the registry? How to scan container within a container? How to cryptographically sign images? Identifying known registries Process for managing the content in a registry (tagging, versioning/naming, etc) Automated policies (patch management, getting new content, etc.) Topic 4 - Once we have secure content (building blocks) and a secure place to store the container images, we need to think about a secure supply chain of the software - the build process.Does a platform require containers, or can it accept code? Can it manage secure builds? How to build automated triggers for builds? How to audit those triggers (webhooks, etc.)? How to validate / scan / test code at different stages of a pipeline? (static analysis, dynamic analysis, etc.) How to promote images to a platform? (automated, manual promotion, etc.)Feedback?Email: PodCTL at gmail dot comTwitter: @PodCTL Web: http://podctl.com

Episode metadata supplied by the publisher feed · Published Nov 6, 2017

Show: 14 Show Overview: Brian and Tyler talk address some of the many layers of security required in a container environment. This show will be part of a series on container and Kubernetes security. They look at security requirement in the Container Host, Container Content, Container Registry, and Software Build Processes. Show Notes and News: 10 Layers of Container SecurityGoogle, VMware and Pivotal announced a Hybrid Cloud partnership with KubernetesGoogle and Cisco announced...

PodParley-generated summary based on available episode metadata and transcript content.

NOW PLAYING

Security: Hosts, Registries, Content and Pipelines

0:00 41:38

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

The Chad James Podcast Chad James Join veteran business coach, Chad James as he challenges you to turn your Boring Old Business into the amazing enterprise you always hoped it would be. Chad shares lessons, stories and strategies from over 20 years of helping small business owners, entrepreneurs and leaders succeed faster, live better and create the lives they always imagined. Everything VR & AR The VRAR Association Everything VR & AR is a weekly podcast covering technologists, enthusiasts, and companies with real world deployments of virtual reality and augmented reality experiences. Learn from interviews with the leaders in gaming, entertainment, productivity, enterprise, social, education, medicine, software, hardware, psychology and more. This podcast covers everything that is VR and AR including the hottest topics and news in virtual reality and augmented reality. Nathan Pettyjohn, Founder of the VR/AR Association is your host. Intel Conversations in the Cloud Intel Intel Conversations in the Cloud is a weekly podcast with IT leaders who are driving the future of a software-defined infrastructure based data center. Featuring members of the Intel Builders programs, Intel experts, and industry analysts, this recurring podcast series provides information on delivering, deploying, and managing cloud computing, technology, and services in the data center and enterprise. Podcast Archive - Today's Business Radio Thomas W Lyons Welcome to TodaysBusinessRadio.com. We are a combination of an on air radio show at KTLK AM 1130, Minneapolis, MN and our online and on demand “business reference library” of over 100 interviews with business advisors, in podcast format. Our mission is to help business owners to: increase enterprise value, improve profitability, control expenses and formulate an exit strategy for the business.

Frequently Asked Questions

How long is this episode of PodCTL - Enterprise Kubernetes?

This episode is 41 minutes long.

When was this PodCTL - Enterprise Kubernetes episode published?

This episode was published on November 6, 2017.

What is this episode about?

Show: 14Show Overview: Brian and Tyler talk address some of the many layers of security required in a container environment. This show will be part of a series on container and Kubernetes security. They look at security requirement in the Container...

Can I download this PodCTL - Enterprise Kubernetes episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!