DIY Pen-Testing for Your Kubernetes Cluster - Liz Rice, Aqua Security
Join us for Kubernetes Forums Seoul, Sydney, Bengaluru and Delhi - learn more at kubecon.io Don't miss KubeCon + CloudNativeCon 2020 events in Amsterdam March 30 - April 2, Shanghai July 28-30 and Boston November 17-20! Learn more at kubecon.io. The conference features presentations from developers and end users of Kubernetes, Prometheus, Envoy, and all of the other CNCF-hosted projects DIY Pen-Testing for Your Kubernetes Cluster - Liz Rice, Aqua Security See how to use kube-hunter to run penetration tests on your Kubernetes clusters, and reveal misconfigurations that might leave you open to attack! Kube-hunter is an open source tool that simulates what a hacker might do when trying to attack a deployment. We’ll discuss the motivations behind the project, and some interesting aspects of how it is implemented. There will be plenty of demos, including: - Testing for the basics, like an unsecured Kubelet API - Simulating an attack from within a compromised container - Re-using credentials from a compromised container You'll need a basic understanding of Kubernetes components, and with using curl to issue API requests. You’ll leave this talk ready to test your own cluster, and with new insights into the possible routes that an attacker might attempt. Perhaps you’ll even be inspired to submit a new Hunter to the project! https://sched.co/MPdo

Effective RBAC - Jordan Liggitt, Red Hat

The Path Less Traveled: Abusing Kubernetes Defaults

Complete Terraform Course - From BEGINNER to PRO! (Learn Infrastructure as Code)

Kubernetes Failure Stories and How to Crash Your Clusters - Henning Jacobs, Zalando SE

Kubernetes Storage 101 - Jan Šafránek, Red Hat & David Zhu, Google
![Life of a Packet [I] - Michael Rubin, Google](https://i.ytimg.com/vi/0Omvgd7Hg1I/hqdefault.jpg?sqp=-oaymwEjCNACELwBSFryq4qpAxUIARUAAAAAGAElAADIQj0AgKJDeAE=&rs=AOn4CLDrL7ag0cePoj42-Q3JCy4xf56bJQ)
Life of a Packet [I] - Michael Rubin, Google

Kubernetes Hacking: From Weak Applications to Cluster Control

Billionaire's WARNING: I'm SELLING. The Crash Is Already Here!

eBPF Superpowers for Go programmers - Liz Rice

LISA19 - Deep Dive into Kubernetes Internals for Builders and Operators

How Does Google Release Kubernetes in GKE - Kobi Magnezi & Josh Hoak, Google

Rootless Containers from Scratch - Liz Rice, Aqua Security
![Certifik8s: All You Need to Know About Certificates in Kubernetes [I] - Alexander Brand, Apprenda](https://i.ytimg.com/vi/gXz4cq3PKdg/hqdefault.jpg?sqp=-oaymwEjCNACELwBSFryq4qpAxUIARUAAAAAGAElAADIQj0AgKJDeAE=&rs=AOn4CLAeW6BBxJhyUkrkvbVn6MCp5vLXuw)
Certifik8s: All You Need to Know About Certificates in Kubernetes [I] - Alexander Brand, Apprenda

The World's Most Important Machine

Liberating Kubernetes From Kube-proxy and Iptables - Martynas Pumputis, Cilium

OAuth 2.0 and OpenID Connect (in plain English)

Attacking and Detecting Attacks on Kubernetes Clusters

Kubernetes Security Best Practices - Ian Lewis (Google)

What Have Namespaces Done for You Lately?

