DevOps and Docker Talk: Cloud Native Interviews and Tooling

Kubescape Kubernetes Security with ARMO


Listen Later

😇 My new GitHub Security workshop has launched! A free 2-hour workshop with hands-on labs to harden your repos and your workflows from common supply chain attacks. I'll cover how attackers are getting in, and then we'll lock down a sample repo so you know what needs to be done to protect your code. You'll leave with a deep understanding of risks and mitigations as well as a list of helpful tools to keep your repos safe, including my new "gasa" tool for scanning your repos and orgs.


Bret is joined by Shauli Rozen, CEO and Co-Founder of ARMO, creators of Kubescape. Kubescape is a K8s open-source tool providing a multi-cloud K8s single pane of glass, including risk analysis, security compliance, RBAC visualizer, and image vulnerability scanning.


I'm a fan of tools like this and specifically of Kubescape, which I use and recommend to my clients. The scanner can scan your YAML manifests of your Kubernetes resources. It can scan your live Kubernetes clusters. And it can scan the YAML in your Git repos, as well as the images themselves that you're deploying to Kubernetes. As ARMO calls it, it's a single pane of glass into your Kubernetes security.

 
Streamed live on YouTube on September 1, 2022. Includes demos.


Unedited live recording of this show on YouTube (Ep #182)


★Topics★
Kubescape's GitHub
K8s Security Dashboard
ARMO website


★Shauli Rozen★
Shauli on Twitter


★Join my Community★

Best coupons for my Docker and Kubernetes courses

Chat with us and fellow students on our Discord Server DevOps Fans

Homepage bretfisher.com

  • (00:00) - DDT MAIN
  • (00:04) - Main intro
  • (00:53) - Custom intro
  • (02:45) - Main show
  • (02:49) - Introductions
  • (03:43) - The Kubescape project
  • (04:25) - Go to the developers
  • (05:26) - Security low-handing fruit
  • (06:19) - I just want to be a user
  • (09:32) - Kubescape elevator pitch
  • (12:00) - Good learning tool
  • (12:48) - Linting
  • (13:20) - Remediation
  • (14:45) - The SaaS Version
  • (16:19) - Does DevOps not care about security?
  • (18:24) - A gap in terminology
  • (20:31) - Security compliance and guidance
  • (25:58) - GitOps Approach
  • (27:38) - Asking about demo
  • (28:19) - Question
  • (29:21) - Become a contributor
  • (30:55) - Demo intro
  • (31:21) - Demo end part
  • (31:26) - Question
  • (31:56) - Visualizer
  • (33:23) - Question
  • (34:41) - Question
  • (38:55) - Mindset differences
  • (39:49) - Question
  • (42:06) - Question
  • (42:33) - Winding down
  • (43:26) - How to get started
  • (44:26) - Template outro

  • You can also support this podcast by subscribing to my YouTube channel and my monthly newsletter at bret.news!

    Grab the best coupons for my GitHub, Agents, Docker, and Kubernetes courses.
    Join my cloud native DevOps community on Discord.
    Grab some merch at Bret's Loot Box
    Homepage bretfisher.com

    ...more
    View all episodesView all episodes
    Download on the App Store

    DevOps and Docker Talk: Cloud Native Interviews and ToolingBy Bret Fisher

    • 4.6
    • 4.6
    • 4.6
    • 4.6
    • 4.6

    4.6

    54 ratings


    More shows like DevOps and Docker Talk: Cloud Native Interviews and Tooling

    View all
    The Joe Rogan Experience by Joe Rogan

    The Joe Rogan Experience

    228,383 Listeners

    All Ears English Podcast by Lindsay McMahon and Michelle Kaplan

    All Ears English Podcast

    2,237 Listeners

    The Daily by The New York Times

    The Daily

    111,948 Listeners

    Agentic DevOps : AI Engineering for Infrastructure by Bret Fisher

    Agentic DevOps : AI Engineering for Infrastructure

    2 Listeners