Kubernetes Security - Seccomp | How to use it to restrict Kernel calls in your Pods

Опубликовано: 23 Октябрь 2024
на канале: Drewbernetes
265
19

Seccomp is part of the Linux Kernel but has gained popularity in the container space due to how much control over syscalls it gives us. We'll take a look at how to implement this useful feature within a Pod to ensure we can restrict the syscalls that can be made from the containers within!

Seccomp Kubernetes: https://kubernetes.io/docs/tutorials/...
Seccomp - RedHat: https://access.redhat.com/documentati...
Seccomp KubeCon talk:    • Securing Kubernetes Applications by C...  
Security Profiles Operator: https://github.com/kubernetes-sigs/se...

00:00 - Intro
00:50 - Policies
03:03 - Using the Policies
07:02 - How To Get Syscalls
12:59 - Wrap Up