DevOps and Docker Talk: Cloud Native Interviews and Tooling

Trivy and Tracee, Aqua Security Tools


Listen Later

šŸ™Œ My next course is coming soon! I've opened the waitlist for those wanting to go deep in GitHub Actions for DevOps and AI automation in 2025. I'm so thrilled to announce this course. The waitlist allows you to quickly sign up for some content updates, discounts, and more as I finish building the course. https://learn.bretfisher.com/waitlistšŸ¾


Bret is joined by AnaĆÆs Urlichs of Aqua Security to talk container and Kubernetes security tools like trivy, kube-bench, tracee, and kube-hunter. I've been using trivy for over four years to scan for known vulnerabilities in my own container images and my clients.

We also look at tracee, a new tool that is part of a new generation of tools that use the Linux kernel eBPF feature to investigate what's happening in real time on your servers. AnaĆÆs is great as an explainer of Kubernetes and all cloud native things, and she's the creator of the 100 days of Kubernetes tutorials on her YouTube channel where she breaks down various cloud native topics for beginners. Based on what I've learned in this show from AnaĆÆs, I plan to change how I use trivy so that it's scanning more things and more often in my CI automation pipelines.

Streamed live on YouTube on November 3, 2022.


Unedited live recording of this show on YouTube (Ep #190)

ā˜…Topicsā˜…
Aqua Security Tools
Aqua Security on YouTube
Trivy
Trivy-Operator
kube-bench
tracee
kube-hunter

ā˜…AnaĆÆs Urlichsā˜…
AnaĆÆs on Twitter
AnaĆÆs' Newsletter
AnaĆÆs on YouTube
100 Days of Kubernetes

ā˜…Join my Communityā˜…
New live course on CI automation and gitops deployments
Best coupons for my Docker and Kubernetes courses
Chat with us and fellow students on our Discord Server DevOps Fans
Grab some merch at Bret's Loot Box

Homepage bretfisher.com

  • (00:00) - DDT MAIN
  • (00:04) - Intro
  • (02:30) - Custom intro
  • (04:05) - Main show
  • (04:09) - Introducing Anais
  • (06:07) - Security Tools
  • (06:33) - What is Aqua Security
  • (07:49) - Not all security scanners are made equal
  • (08:59) - What is Trivy?
  • (09:38) - Misconfiguration scanning with Trivy
  • (13:49) - Security vs Disruption
  • (14:43) - Address vulnerabilities in the base image
  • (15:48) - Question: Operator for Trivy
  • (19:28) - Automating the tool
  • (21:22) - Vulnerability fatigue
  • (22:09) - Question: Go and No-go Criteria
  • (25:50) - Tip Toe, Start Small
  • (26:56) - Kube Bench
  • (27:45) - Kube Hunter
  • (29:46) - What is Tracee?
  • (35:16) - What is the roadmap for implementing these tools?
  • (41:34) - Outro

  • You can also support my free material by subscribing to my YouTube channel and my weekly newsletter at bret.news!

    Grab the best coupons for my Docker and Kubernetes courses.
    Join my cloud native DevOps community on Discord.
    Grab some merch at Bret's Loot Box
    Homepage bretfisher.com

    ...more
    View all episodesView all episodes
    Download on the App Store

    DevOps and Docker Talk: Cloud Native Interviews and ToolingBy Bret Fisher

    • 4.6
    • 4.6
    • 4.6
    • 4.6
    • 4.6

    4.6

    54 ratings


    More shows like DevOps and Docker Talk: Cloud Native Interviews and Tooling

    View all
    The Knowledge Project by Shane Parrish

    The Knowledge Project

    2,688 Listeners

    6 Minute English by BBC Radio

    6 Minute English

    1,757 Listeners

    Learning English Conversations by BBC Radio

    Learning English Conversations

    1,038 Listeners

    The Diary Of A CEO with Steven Bartlett by DOAC

    The Diary Of A CEO with Steven Bartlett

    8,618 Listeners

    Kubernetes Podcast from Google by Abdel Sghiouar, Kaslin Fields

    Kubernetes Podcast from Google

    181 Listeners

    Day Two DevOps by Packet Pushers

    Day Two DevOps

    15 Listeners

    DevOps Paradox by Darin Pope & Viktor Farcic

    DevOps Paradox

    25 Listeners

    Adventures in DevOps by Will Button, Warren Parad

    Adventures in DevOps

    18 Listeners

    Think Fast Talk Smart: Communication Techniques by Matt Abrahams, Think Fast Talk Smart

    Think Fast Talk Smart: Communication Techniques

    798 Listeners

    All-In with Chamath, Jason, Sacks & Friedberg by All-In Podcast, LLC

    All-In with Chamath, Jason, Sacks & Friedberg

    9,935 Listeners

    Coaching Real Leaders by Harvard Business Review / Muriel Wilkins

    Coaching Real Leaders

    676 Listeners

    The Ezra Klein Show by New York Times Opinion

    The Ezra Klein Show

    15,948 Listeners

    The Foreign Affairs Interview by Foreign Affairs Magazine

    The Foreign Affairs Interview

    445 Listeners

    The Rest Is Politics: US by Goalhanger

    The Rest Is Politics: US

    2,204 Listeners

    Agentic DevOps by Bret Fisher

    Agentic DevOps

    2 Listeners