DevOps and Docker Talk: Cloud Native Interviews and Tooling

Securing Containers, First Steps in Docker and Kubernetes


Listen Later

🙌 My next course is coming soon! I've opened the waitlist for those wanting to go deep in GitHub Actions for DevOps and AI automation in 2025. I'm so thrilled to announce this course. The waitlist allows you to quickly sign up for some content updates, discounts, and more as I finish building the course. https://learn.bretfisher.com/waitlistđŸŸ


Bret goes through his top recommendations for securing container images, Docker containers and Kubernetes pods.

This is a tip-packed show where Bret lists much of what's documented in his courses, starting with the first steps you should take, and the bare security necessities that everyone should be doing. Then he covers more advanced security activities you should consider once the basics are covered.

Streamed live on YouTube on July 7, 2022.


Unedited live recording of this show on YouTube (Ep #177).


★Topics★
Bret's Container Security AMA
Docker Security Docs
Docker Buys Atomist
Slim.ai website: Auto-slimming images
Docker Slim tool
Kubescape website
Kubernetes Security Context
Seccomp by default
Lint all files with super-linter
Datree K8s file scan
Kubernetes Benchmark
My GitHub Actions examples: Automate your builds, CVE scans, and more
Video on building a more secure base image
Snyk security tools website
Trivy CVE and K8s scans
Falco for watching servers for bad behavior

★Join my Community★
Best coupons for my Docker and Kubernetes courses

Chat with us on our Discord Server Vital DevOps

Homepage bretfisher.com

  • (00:00) - Intro
  • (00:52) - Mid-Roll Intro
  • (00:53) - Bret's Intro
  • (03:23) - Main show
  • (04:22) - What should I worry about first? The Basics!
  • (05:24) - Start with images
  • (06:05) - Bret.show/SecurityFirst
  • (06:41) - CVE scanning
  • (07:13) - Dependency scanning
  • (08:05) - Bret's Github with Dependabot
  • (09:02) - OS dependencies with Trivy and Snyk
  • (11:00) - Bret's Talks
  • (11:54) - Alpine is not always good
  • (13:04) - All hands on automation
  • (13:51) - Don't run as root inside the image
  • (15:41) - Question
  • (16:57) - Making slimmer images
  • (17:29) - Atomist
  • (18:56) - DockerSlim
  • (22:25) - Question
  • (23:58) - Question
  • (25:46) - Question
  • (26:13) - Question
  • (26:22) - Question
  • (26:52) - Securing Docker
  • (27:24) - Docker host scanner
  • (28:05) - Falco
  • (28:32) - Just use Docker
  • (30:05) - Question about Windows Containers
  • (31:56) - Maintain your servers
  • (32:49) - Docker in the cloud
  • (34:06) - Always stay on the latest Kubernetes release
  • (35:10) - Kube-bench
  • (35:59) - Tree.io
  • (36:41) - Pod specs
  • (37:45) - Sec comp
  • (39:10) - Security context
  • (40:34) - Privilege escalation
  • (41:27) - Superlinter
  • (42:31) - Question about Fargate
  • (44:12) - Network policies
  • (46:15) - Kubernetes docs article on security context
  • (46:53) - Question
  • (49:20) - Third-party security monitoring
  • (49:34) - Question about volumes
  • (50:22) - Question about Docker subnets
  • (51:07) - Question about secrets
  • (51:54) - Question about subnets 2
  • (52:25) - Question
  • (54:40) - Outro

  • You can also support my free material by subscribing to my YouTube channel and my weekly newsletter at bret.news!

    Grab the best coupons for my Docker and Kubernetes courses.
    Join my cloud native DevOps community on Discord.
    Grab some merch at Bret's Loot Box
    Homepage bretfisher.com

    ...more
    View all episodesView all episodes
    Download on the App Store

    DevOps and Docker Talk: Cloud Native Interviews and ToolingBy Bret Fisher

    • 4.6
    • 4.6
    • 4.6
    • 4.6
    • 4.6

    4.6

    54 ratings


    More shows like DevOps and Docker Talk: Cloud Native Interviews and Tooling

    View all
    The Knowledge Project by Shane Parrish

    The Knowledge Project

    2,688 Listeners

    6 Minute English by BBC Radio

    6 Minute English

    1,754 Listeners

    Learning English Conversations by BBC Radio

    Learning English Conversations

    1,038 Listeners

    The Diary Of A CEO with Steven Bartlett by DOAC

    The Diary Of A CEO with Steven Bartlett

    8,469 Listeners

    Kubernetes Podcast from Google by Abdel Sghiouar, Kaslin Fields

    Kubernetes Podcast from Google

    181 Listeners

    Day Two DevOps by Packet Pushers

    Day Two DevOps

    15 Listeners

    DevOps Paradox by Darin Pope & Viktor Farcic

    DevOps Paradox

    25 Listeners

    Adventures in DevOps by Will Button, Warren Parad

    Adventures in DevOps

    18 Listeners

    Think Fast Talk Smart: Communication Techniques by Matt Abrahams, Think Fast Talk Smart

    Think Fast Talk Smart: Communication Techniques

    798 Listeners

    All-In with Chamath, Jason, Sacks & Friedberg by All-In Podcast, LLC

    All-In with Chamath, Jason, Sacks & Friedberg

    9,935 Listeners

    Coaching Real Leaders by Harvard Business Review / Muriel Wilkins

    Coaching Real Leaders

    676 Listeners

    The Ezra Klein Show by New York Times Opinion

    The Ezra Klein Show

    15,948 Listeners

    The Foreign Affairs Interview by Foreign Affairs Magazine

    The Foreign Affairs Interview

    445 Listeners

    The Rest Is Politics: US by Goalhanger

    The Rest Is Politics: US

    2,204 Listeners

    Agentic DevOps by Bret Fisher

    Agentic DevOps

    2 Listeners