
Kubernetes Podcast from Google
Attacking and Defending Kubernetes, with Ian Coldwater
Aug 6, 2019 · 43 min · Episode 65 · 62.4 MB
0:00-43:19
Streams straight from the publisher. podnod never proxies or re-hosts episode audio.
Ian Coldwater specializes in breaking and hardening Kubernetes, containers, and cloud native infrastructure. A pre-eminent voice in the Kubernetes security community, they are currently a Lead Platform Security Engineer at Heroku. Ian joins Adam and Craig to talk about the offensive and defensive arts.
Do you have something cool to share? Some questions? Let us know:
- web: kubernetespodcast.com
- mail: kubernetespodcast@google.com
- twitter: @kubernetespod
- Mesosphere becomes D2iQ
- Google Cloud launches Migrate for Anthos in Beta
- Google Cloud Game Servers coming soon
- Announcing Kubernetes Summits in Seoul and Sydney
- Security updates of the week
- IBM and Red Hat:
- Cisco Container Platform now supports Microsoft AKS
- Helm deployments at the Kubedex
- How Kubernetes can be used for genetic analysis by Mu Huan and Eric Li Alibaba Cloud
- Announcing CloudBees Jenkins X Distribution
- TiDB Operator now Generally Available
- Red teams and penetration testing
- Fuzzing
- Attacking Helm's Tiller
- Black-box and white-box testing
- DevSecOps: guard rails, not gates
- OWASP - the Open Web Application Security Project
- The math behind calculating security risk
- CVSS score
- etcd: encrypt it at rest!
- Admission control
- Technologies for isolation:
- AppArmor
- Seccomp
- gVisor
- Firecracker (not yet supported with Kubernetes)
- "Kubernetes is powerful, and it's insecure by design"
- Threat modelling
- hostpath - "a powerful escape hatch"
- Trail of Bits blog: understanding Docker container escapes
- Recommended watching:
- Ship of Fools by Ian Coldwater (slides)
- Hacking and Hardening Kubernetes by Example by Brad Geesaman (slides)
- A Hackers Guide to Kubernetes and the Cloud by Rory McCune (and his upcoming Black Hat training)
- DIY Pen Testing for your Kubernetes Cluster by Liz Rice (our guest on episode 19)
- Ian Coldwater on Twitter
Ian Coldwater
twitter.comAdam and Craig
kubernetespodcast.comkubernetespodcast.com
kubernetespodcast.com@kubernetespod
twitter.comBlack Hat USA
blackhat.comDEFCON
defcon.orgScavenger hunts
defconscavhunt.comAn example of Spot the Fed
vice.comAn example of the Mystery Challenge
wired.comMesosphere becomes D2iQ
techcrunch.comGoogle Cloud launches Migrate for Anthos in Beta
cloud.google.comGoogle Cloud Game Servers coming soon
cloud.google.comEpisode 26: Agones, with Mark Mandel and Cyril Tovena
kubernetespodcast.comSecurity updates of the week
groups.google.comCVE-2019-11249: kubectl cp
github.comOpenShift on IBM Cloud
ibm.comCloud Paks and services
ibm.comCisco Container Platform now supports Microsoft AKS
blogs.cisco.comHelm deployments at the Kubedex
kubedex.comAnnouncing CloudBees Jenkins X Distribution
cloudbees.comEpisode 44, Continuous Delivery Foundation, with Tracy Miranda
kubernetespodcast.comTiDB Operator now Generally Available
pingcap.comRed teams
en.wikipedia.orgpenetration testing
en.wikipedia.orgFuzzing
en.wikipedia.orgAttacking Helm's Tiller
blog.ropnop.comBlack-box
en.wikipedia.orgwhite-box
en.wikipedia.orgDevSecOps: guard rails, not gates
blog.sonatype.comOWASP
owasp.orgCVSS score
en.wikipedia.orgetcd: encrypt it at rest!
kubernetes.ioAdmission control
kubernetes.ioAppArmor
kubernetes.ioSeccomp
kubernetes.iogVisor
gvisor.devFirecracker
firecracker-microvm.github.ioIan and Duffie Cooley's BlackHat talk
blackhat.comCloud doesn't make it better!
twitter.comThreat modelling
en.wikipedia.orghostpath
kubernetes.ioTrail of Bits blog
blog.trailofbits.comShip of Fools
youtube.comslides
sans.orgHacking and Hardening Kubernetes by Example
youtube.comslides
github.comA Hackers Guide to Kubernetes and the Cloud
youtube.comupcoming Black Hat training
blackhat.comDIY Pen Testing for your Kubernetes Cluster
youtube.comour guest on episode 19
kubernetespodcast.com