Get in Touch
 Duration 21 hours

Course Outline

Cluster Setup

  • Implement Network security policies to restrict cluster-level access.
  • Apply CIS benchmarks to review the security configurations of Kubernetes components (etcd, kubelet, kubedns, kubeapi).
  • Configure Ingress objects with appropriate security controls.
  • Safeguard node metadata and endpoints.
  • Limit the use of, and access to, GUI elements.
  • Verify platform binaries prior to deployment.

Cluster Hardening

  • Restrict access to the Kubernetes API.
  • Leverage Role Based Access Controls to minimize exposure.
  • Exercise caution with service accounts, such as disabling defaults and minimizing permissions on newly created ones.
  • Keep Kubernetes up to date through frequent updates.

System Hardening

  • Reduce the host OS footprint to minimize the attack surface.
  • Minimize IAM roles.
  • Limit external access to the network.
  • Utilize kernel hardening tools such as AppArmor and seccomp appropriately.

Minimize Microservice Vulnerabilities

  • Establish appropriate OS-level security domains using tools like PSP, OPA, and security contexts.
  • Manage Kubernetes secrets effectively.
  • Employ container runtime sandboxes in multi-tenant environments (e.g., gvisor, kata containers).
  • Implement pod-to-pod encryption via mTLS.

Supply Chain Security

  • Minimize the base image footprint.
  • Secure the supply chain by whitelisting allowed image registries, and signing and validating images.
  • Perform static analysis of user workloads (e.g., Kubernetes resources, Dockerfiles).
  • Scan images for known vulnerabilities.

Monitoring, Logging and Runtime Security

  • Conduct behavioral analytics of syscall processes and file activities at both the host and container levels to detect malicious activity.
  • Identify threats within physical infrastructure, applications, networks, data, users, and workloads.
  • Detect all phases of attacks, regardless of their origin or method of spread.
  • Perform deep analytical investigations to identify bad actors within the environment.
  • Ensure the immutability of containers at runtime.
  • Use Audit Logs to monitor access patterns.

Requirements

  • CKA (Certified Kubernetes Administrator) certification

Target Audience

  • Kubernetes practitioners

Custom Corporate Training

Training solutions designed exclusively for businesses.

  • Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
  • Flexible Schedule: Dates and times adapted to your team's agenda.
  • Format: Online (live), In-company (at your offices), or Hybrid.
Investment

Price per private group, online live training, starting from 3900 € + VAT*

Contact us for an exact quote and to hear our latest promotions

Testimonials (4)

Provisional Upcoming Courses (Contact Us For More Information)

Related Categories