Kubernetes Podcast from Google

Attacking and Defending Kubernetes, with Ian Coldwater


Listen Later

Ian Coldwater specializes in breaking and hardening Kubernetes, containers, and cloud native infrastructure. A pre-eminent voice in the Kubernetes security community, they are currently a Lead Platform Security Engineer at Heroku. Ian joins Adam and Craig to talk about the offensive and defensive arts.

Do you have something cool to share? Some questions? Let us know:

Chatter of the week
  • Black Hat USA
  • DEFCON
    • Scavenger hunts
    • An example of Spot the Fed
    • An example of the Mystery Challenge
News of the week
  • Mesosphere becomes D2iQ
  • Google Cloud launches Migrate for Anthos in Beta
  • Google Cloud Game Servers coming soon
    • Episode 26: Agones, with Mark Mandel and Cyril Tovena
  • Announcing Kubernetes Summits in Seoul and Sydney
  • Security updates of the week
    • CVE-2019-11247: API server allows access to custom resources via wrong scope
    • CVE-2019-11249: kubectl cp (round 3!)
  • IBM and Red Hat:
    • OpenShift on IBM Cloud
    • OpenShift coming to Z Series and LinuxONE
    • Cloud Paks and services
  • Cisco Container Platform now supports Microsoft AKS
  • Helm deployments at the Kubedex
  • How Kubernetes can be used for genetic analysis by Mu Huan and Eric Li Alibaba Cloud
  • Announcing CloudBees Jenkins X Distribution
    • Episode 44, Continuous Delivery Foundation, with Tracy Miranda
  • TiDB Operator now Generally Available
Links from the interview
  • Red teams and penetration testing
  • Fuzzing
  • Attacking Helm’s Tiller
  • Black-box and white-box testing
  • DevSecOps: guard rails, not gates
  • OWASP - the Open Web Application Security Project
  • The math behind calculating security risk
  • CVSS score
  • etcd: encrypt it at rest!
  • Admission control
  • Technologies for isolation:
    • AppArmor
    • Seccomp
    • gVisor
    • Firecracker (not yet supported with Kubernetes)
  • “Kubernetes is powerful, and it’s insecure by design”
    • Ian and Duffie Cooley’s BlackHat talk
    • Cloud doesn’t make it better!
  • Threat modelling
  • hostpath - “a powerful escape hatch”
    • Trail of Bits blog: understanding Docker container escapes
  • Recommended watching:
    • Ship of Fools by Ian Coldwater (slides)
    • Hacking and Hardening Kubernetes by Example by Brad Geesaman (slides)
    • A Hackers Guide to Kubernetes and the Cloud by Rory McCune (and his upcoming Black Hat training)
    • DIY Pen Testing for your Kubernetes Cluster by Liz Rice (our guest on episode 19)
  • Ian Coldwater on Twitter
...more
View all episodesView all episodes
Download on the App Store

Kubernetes Podcast from GoogleBy Abdel Sghiouar, Kaslin Fields

  • 4.8
  • 4.8
  • 4.8
  • 4.8
  • 4.8

4.8

180 ratings


More shows like Kubernetes Podcast from Google

View all
Hanselminutes with Scott Hanselman by Scott Hanselman

Hanselminutes with Scott Hanselman

377 Listeners

Software Engineering Radio - the podcast for professional software developers by se-radio@computer.org

Software Engineering Radio - the podcast for professional software developers

272 Listeners

The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

282 Listeners

The Cloudcast by Massive Studios

The Cloudcast

152 Listeners

Thoughtworks Technology Podcast by Thoughtworks

Thoughtworks Technology Podcast

42 Listeners

Talk Python To Me by Michael Kennedy

Talk Python To Me

590 Listeners

Software Engineering Daily by Software Engineering Daily

Software Engineering Daily

626 Listeners

AWS Podcast by Amazon Web Services

AWS Podcast

203 Listeners

Data Engineering Podcast by Tobias Macey

Data Engineering Podcast

141 Listeners

Syntax - Tasty Web Development Treats by Wes Bos & Scott Tolinski - Full Stack JavaScript Web Developers

Syntax - Tasty Web Development Treats

984 Listeners

Practical AI by Practical AI LLC

Practical AI

189 Listeners

The Stack Overflow Podcast by The Stack Overflow Podcast

The Stack Overflow Podcast

64 Listeners

The Real Python Podcast by Real Python

The Real Python Podcast

140 Listeners

Oxide and Friends by Oxide Computer Company

Oxide and Friends

47 Listeners

The Pragmatic Engineer by Gergely Orosz

The Pragmatic Engineer

52 Listeners