CONTACT ONS

Cursusaanbod

Cluster Setup

  • Apply Network security policies to limit cluster-level access
  • Leverage CIS benchmarks to assess the security settings of Kubernetes components (etcd, kubelet, kubedns, kubeapi)
  • Configure Ingress objects with appropriate security controls
  • Safeguard node metadata and endpoints
  • Limit the usage of, and access to, GUI elements
  • Validate platform binaries prior to deployment

Cluster Hardening

  • Limit access to the Kubernetes API
  • Employ Role Based Access Controls to reduce exposure
  • Exercise caution with service accounts, such as disabling defaults and minimizing permissions for new accounts
  • Keep Kubernetes up to date with frequent updates

System Hardening

  • Reduce the host OS footprint to minimize the attack surface
  • Streamline IAM roles
  • Limit external network access
  • Utilize kernel hardening tools such as AppArmor and seccomp effectively

Minimizing Microservice Vulnerabilities

  • Establish appropriate OS-level security domains using PSP, OPA, or security contexts
  • Manage Kubernetes secrets securely
  • Employ container runtime sandboxes in multi-tenant settings (e.g., gvisor, kata containers)
  • Implement pod-to-pod encryption via mTLS

Supply Chain Security

  • Reduce the base image footprint
  • Secure the supply chain by whitelisting approved image registries and signing and verifying images
  • Conduct static analysis of user workloads (e.g., Kubernetes resources, Dockerfiles)
  • Scan images for known vulnerabilities

Monitoring, Logging, and Runtime Security

  • Analyze syscall processes and file activities at both host and container levels to detect malicious behavior
  • Identify threats across physical infrastructure, applications, networks, data, users, and workloads
  • Detect all phases of an attack, regardless of its origin or propagation
  • Conduct deep analytical investigations to identify malicious actors within the environment
  • Maintain container immutability during runtime
  • Use Audit Logs to monitor access activities

Vereisten

  • CKA (Certified Kubernetes Administrator)-certificering

Doelgroep

  • Kubernetes-praktijken
 21 Uren

Aangepaste bedrijfsopleiding

Opleidingsoplossingen ontworpen exclusief voor bedrijven.

  • Aangepaste inhoud: We passen de syllabus en praktijkopdrachten aan naar de echte doelen en behoeften van uw project.
  • Voor flexibel schema: Datums en tijden aangepast aan het rooster van uw team.
  • Formaat: Online (live), In-company (bij uw kantoren) of Hybride.
Investering

Prijs per privégroep, online live training, startend vanaf 4800 € + BTW*

Neem contact met ons op voor een exacte offerte en om onze laatste promoties te horen

Reviews (4)

Voorlopige Aankomende Cursussen

Gerelateerde categorieën