Hacking Kubernetes: Threat-Driven Analysis and Defense

Hacking Kubernetes: Threat-Driven Analysis and Defense

作者: Martin Andrew Hausenblas Michael
出版社: O'Reilly
出版在: 2021-11-02
ISBN-13: 9781492081739
ISBN-10: 1492081736
裝訂格式: Quality Paper - also called trade paper
總頁數: 314 頁





內容描述


Want to run your Kubernetes workloads safely and securely? This practical book provides a threat-based guide to Kubernetes security. Each chapter examines a particular component's architecture and potential default settings and then reviews existing high-profile attacks and historical Common Vulnerabilities and Exposures (CVEs). Authors Andrew Martin and Michael Hausenblas share best-practice configuration to help you harden clusters from possible angles of attack.
This book begins with a vanilla Kubernetes installation with built-in defaults. You'll examine an abstract threat model of a distributed system running arbitrary workloads, and then progress to a detailed assessment of each component of a secure Kubernetes system.

Understand where your Kubernetes system is vulnerable with threat modelling techniques
Focus on pods, from configurations to attacks and defenses
Secure your cluster and workload traffic
Define and enforce policy with RBAC, OPA, and Kyverno
Dive deep into sandboxing and isolation techniques
Learn how to detect and mitigate supply chain attacks
Explore filesystems, volumes, and sensitive information at rest
Discover what can go wrong when running multitenant workloads in a cluster
Learn what you can do if someone breaks in despite you having controls in place


作者介紹


Andrew Martin is CEO of ControlPlane.
Michael Hausenblas is Product Developer Advocate Amazon Web Service.




相關書籍

Beginning PowerShell for SharePoint 2016: A Guide for Administrators, Developers, and DevOps Engineers

作者 Nikolas Charlebois-Laprade John Edward Naguib

2021-11-02

Mastering Kubernetes - Third Edition: Level up your container orchestration skills with Kubernetes to build, run, secure, and observe large-scale dist

作者 Gigi Sayfan

2021-11-02

Implementing Microsoft Azure Architect Technologies AZ-303 Exam Prep and Beyond - Second Edition: A guide to preparing for the AZ-303 Microsoft Azure

作者 Hargreaves Brett Zaal Sjoukje

2021-11-02