Get in Touch
 Duration 21 hours

Course Outline

Cluster Setup

  • Apply Network security policies to limit cluster-level access
  • Leverage CIS benchmarks to assess the security settings of Kubernetes components (etcd, kubelet, kubedns, kubeapi)
  • Configure Ingress objects with appropriate security controls
  • Safeguard node metadata and endpoints
  • Limit the usage of, and access to, GUI elements
  • Validate platform binaries prior to deployment

Cluster Hardening

  • Limit access to the Kubernetes API
  • Employ Role Based Access Controls to reduce exposure
  • Exercise caution with service accounts, such as disabling defaults and minimizing permissions for new accounts
  • Keep Kubernetes up to date with frequent updates

System Hardening

  • Reduce the host OS footprint to minimize the attack surface
  • Streamline IAM roles
  • Limit external network access
  • Utilize kernel hardening tools such as AppArmor and seccomp effectively

Minimizing Microservice Vulnerabilities

  • Establish appropriate OS-level security domains using PSP, OPA, or security contexts
  • Manage Kubernetes secrets securely
  • Employ container runtime sandboxes in multi-tenant settings (e.g., gvisor, kata containers)
  • Implement pod-to-pod encryption via mTLS

Supply Chain Security

  • Reduce the base image footprint
  • Secure the supply chain by whitelisting approved image registries and signing and verifying images
  • Conduct static analysis of user workloads (e.g., Kubernetes resources, Dockerfiles)
  • Scan images for known vulnerabilities

Monitoring, Logging, and Runtime Security

  • Analyze syscall processes and file activities at both host and container levels to detect malicious behavior
  • Identify threats across physical infrastructure, applications, networks, data, users, and workloads
  • Detect all phases of an attack, regardless of its origin or propagation
  • Conduct deep analytical investigations to identify malicious actors within the environment
  • Maintain container immutability during runtime
  • Use Audit Logs to monitor access activities

Requirements

  • CKA (Certified Kubernetes Administrator) certification

Target Audience

  • Professionals practicing Kubernetes

Custom Corporate Training

Training solutions designed exclusively for businesses.

  • Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
  • Flexible Schedule: Dates and times adapted to your team's agenda.
  • Format: Online (live), In-company (at your offices), or Hybrid.
Investment

Price per private group, online live training, starting from 4800 € + VAT*

Contact us for an exact quote and to hear our latest promotions

Testimonials (4)

Provisional Upcoming Courses (Contact Us For More Information)

Related Categories