Seccomp is part of the Linux Kernel but has gained popularity in the container space due to how much control over syscalls it gives us. We'll take a look at how to implement this useful feature within a Pod to ensure we can restrict the syscalls that can be made from the containers within!
Seccomp Kubernetes: https://kubernetes.io/docs/tutorials/...
Seccomp - RedHat: https://access.redhat.com/documentati...
Seccomp KubeCon talk: • Securing Kubernetes Applications by C...
Security Profiles Operator: https://github.com/kubernetes-sigs/se...
00:00 - Intro
00:50 - Policies
03:03 - Using the Policies
07:02 - How To Get Syscalls
12:59 - Wrap Up