Seccomp Security Profiles and You: A Practical Guide - Duffie Cooley, VMware

Don’t miss out! Join us at our upcoming events: EnvoyCon Virtual on October 15 and KubeCon + CloudNativeCon North America 2020 Virtual from November 17-20. Learn more at https://kubecon.io. The conferences feature presentations from developers and end users of Kubernetes, Prometheus, Envoy, and all of the other CNCF-hosted projects. Seccomp Security Profiles and You: A Practical Guide - Duffie Cooley, VMware Have you wondered what a seccomp security profile is, and how it relates to Linux Capabilities? Folks often dismiss seccomp profiles and Capabilities as a way of hardening applications as it is too difficult to determine what syscalls are in use by a given application. In this session we will explore a couple of tools designed to make this more approachable. Dockersl.im is an opensource project that can take a Dockerfile and an image and produce a smaller image containing only the necessary bits, a seccomp security profile derived from the system calls the application made while under test. Inspektor Gadget is an opensource project by the folks at kinvolk that enables to make use of BPF to inspect a number of things about pods that are deployed. Providing better visibility into what pods are accessing from a syscall and filesystem perspective. Come learn about these super powers! https://sched.co/ZetL

Kubernetes On Cgroup v2 - Giuseppe Scrivano, Red Hat
▶︎

Kubernetes On Cgroup v2 - Giuseppe Scrivano, Red Hat

Intro to Falco: Intrusion Detection for Containers - Shane Lawrence, Shopify
▶︎

Intro to Falco: Intrusion Detection for Containers - Shane Lawrence, Shopify

Seccomp and eBPF; What’s the Difference? Why Do I Need to Know? - Natalia Reka Ivanko, Duffie Cooley
▶︎

Seccomp and eBPF; What’s the Difference? Why Do I Need to Know? - Natalia Reka Ivanko, Duffie Cooley

Linus Torvalds: AI Is Changing Linux Fast
▶︎

Linus Torvalds: AI Is Changing Linux Fast

Android 17 sucks. So I put Linux on a phone.
▶︎

Android 17 sucks. So I put Linux on a phone.

Kubernetes Security Best Practices - Ian Lewis, Google
▶︎

Kubernetes Security Best Practices - Ian Lewis, Google

Billionaire's WARNING: I'm SELLING. The Crash Is Already Here!
▶︎

Billionaire's WARNING: I'm SELLING. The Crash Is Already Here!

Docker Core Concepts Every Developer Should Know
▶︎

Docker Core Concepts Every Developer Should Know

Architectural Caching Patterns for Kubernetes - Rafał Leszko, Hazelcast
▶︎

Architectural Caching Patterns for Kubernetes - Rafał Leszko, Hazelcast

Istio - The Packet's-Eye View - Matt Turner, Tetrate
▶︎

Istio - The Packet's-Eye View - Matt Turner, Tetrate

Running K3s, Lightweight Kubernetes, in Production for the Edge & Beyond - Darren Shepherd, Rancher
▶︎

Running K3s, Lightweight Kubernetes, in Production for the Edge & Beyond - Darren Shepherd, Rancher

Tutorial: Using Linux Primitives to Build Your Own Containers - Stéphane Graber & Christian Brauner
▶︎

Tutorial: Using Linux Primitives to Build Your Own Containers - Stéphane Graber & Christian Brauner

Webinar: The abc’s of Kubernetes security
▶︎

Webinar: The abc’s of Kubernetes security

Keynote: After the AI Hype – What’s Real, and What’s Next - Richard Campbell - 2026
▶︎

Keynote: After the AI Hype – What’s Real, and What’s Next - Richard Campbell - 2026

DIY Pen-Testing for Your Kubernetes Cluster - Liz Rice, Aqua Security
▶︎

DIY Pen-Testing for Your Kubernetes Cluster - Liz Rice, Aqua Security

Life of a Packet [I] - Michael Rubin, Google
▶︎

Life of a Packet [I] - Michael Rubin, Google

Docker Security Essentials | How To Secure Docker Containers
▶︎

Docker Security Essentials | How To Secure Docker Containers

Container Security, capabilities an seccomp profiles - Alberto Losada Grande & Mario Vázquez, RedHat
▶︎

Container Security, capabilities an seccomp profiles - Alberto Losada Grande & Mario Vázquez, RedHat

eBPF: Unlocking the Kernel [OFFICIAL DOCUMENTARY]
▶︎

eBPF: Unlocking the Kernel [OFFICIAL DOCUMENTARY]

Kubernetes Deconstructed: Understanding Kubernetes by Breaking It Down - Carson Anderson, DOMO
▶︎

Kubernetes Deconstructed: Understanding Kubernetes by Breaking It Down - Carson Anderson, DOMO