Container & Kubernetes Security workshop

In the previous workshop episodes, you learned the basics of Docker & Kubernetes. This workshop aims to kick a notch higher by introducing you to the security aspects of the container world. In this presentation, you will see live hacking demos, patterns & workflows, along with some insights & hands-on exercises on container security. This workshop aims to point you in the right direction regarding container security! Post knowledge transfer on container security basics, we will co-relate the container security aspects with Kubernetes and other elements of Kubernetes Security. Lastly, we will touch base on some open source tools that will help us harden the Kubernetes environment. Timestamps 00:00 Intro music 1:34 workshop starts 5:33 Hacks happened in the past 7:29 Demo of an Attack 29:25 What is a container? (killercoda demo) 37:05 root inside a container 45:38 privileged container 52:07 Linux capabilities 1:05:12 Kubernetes Goat 1:12:02 Getting a reverse shell 1:23:00 hostPID & hostNetwork 1:25:40 trivy scan on ubuntu & nginx image 1:28:07 Scanning argocd images 1:33:10 distroless images 1:35:28 Analyze your container image with dive 1:41:25 Memory Limits for containers & fork bomb 1:45:10 Kubernetes goat challange (private registry) 1:50:00 Runtime security (falco) 1:55:12 Kubernetes Security 2:04:35 kubectl-fields plugin 2:06:55 Network Policies 2:14:30 kyverno (admission controller) 2:19:30 kubescape for static scanning 2:26:10 closing message Speaker - Rewanth Tammana (@rewanthtammana) ►►►Resources ►►► ► Prerequisite -    • Kubernetes 101 workshop - complete hands-on   ► GitHub Repo - https://github.com/rewanthtammana/con... ► Killercoda Playground - https://killercoda.com/playgrounds/sc... ►►►Connect with Kubesimplify ►►► ► Twitter -   / kubesimplify   ► Discord - https://kubesimplify.com/discord ► Website - https://kubesimplify.com/ ► GitHub - https://github.com/kubesimplify

Confidential Computing on Kubernetes with Moritz | Live Workshop
▶︎

Confidential Computing on Kubernetes with Moritz | Live Workshop

Billionaire's WARNING: I'm SELLING. The Crash Is Already Here!
▶︎

Billionaire's WARNING: I'm SELLING. The Crash Is Already Here!

Chaos engineering with Litmus - Complete hands-on workshop
▶︎

Chaos engineering with Litmus - Complete hands-on workshop

JANITOR vs THE BIGGEST GUYS IN THE GYM. They Didn’t Expect THAT
▶︎

JANITOR vs THE BIGGEST GUYS IN THE GYM. They Didn’t Expect THAT

Free Event: Power BI Beginner to Pro 2026 Edition - Full Hands-On Tutorial
▶︎

Free Event: Power BI Beginner to Pro 2026 Edition - Full Hands-On Tutorial

Complete Kubernetes Course - From BEGINNER to PRO
▶︎

Complete Kubernetes Course - From BEGINNER to PRO

Why Did These Pilots LIE to the Controller?! | Indian Airlines Flight 257
▶︎

Why Did These Pilots LIE to the Controller?! | Indian Airlines Flight 257

Zig 2026: No-AI Policy, $670K Foundation, Left GitHub & Why Zig Isn’t 1.0 - Andrew Kelley Explains
▶︎

Zig 2026: No-AI Policy, $670K Foundation, Left GitHub & Why Zig Isn’t 1.0 - Andrew Kelley Explains

Kubernetes and retiring at the top with Kelsey Hightower
▶︎

Kubernetes and retiring at the top with Kelsey Hightower

Linux & Docker Fundamentals - complete hands-on workshop
▶︎

Linux & Docker Fundamentals - complete hands-on workshop

What is SonarQube | Introduction SonarQube | SonarQube Tutorial | SonarQube Basics | Intellipaat
▶︎

What is SonarQube | Introduction SonarQube | SonarQube Tutorial | SonarQube Basics | Intellipaat

Kubernetes Zero to Hero: The Complete Beginner’s Guide (2025 Edition)
▶︎

Kubernetes Zero to Hero: The Complete Beginner’s Guide (2025 Edition)

Avicii, Dua Lipa, Coldplay, Martin Garrix & Kygo, The Chainsmokers Style - Summer Vibes #21
▶︎

Avicii, Dua Lipa, Coldplay, Martin Garrix & Kygo, The Chainsmokers Style - Summer Vibes #21

Full Archon Guide - Build AI Coding Harnesses That Actually Ship (LIVE)
▶︎

Full Archon Guide - Build AI Coding Harnesses That Actually Ship (LIVE)

Creator of C++: Bell Labs, Negative Overhead Abstraction, Mistakes | Bjarne Stroustrup
▶︎

Creator of C++: Bell Labs, Negative Overhead Abstraction, Mistakes | Bjarne Stroustrup

Microsoft Just Released Their Own Linux Distro: Should You Be Worried?
▶︎

Microsoft Just Released Their Own Linux Distro: Should You Be Worried?

Designing Data-Intensive Applications: Chapters 1 and 2
▶︎

Designing Data-Intensive Applications: Chapters 1 and 2

Linux Full Course for Beginners | Learn Linux System Administration
▶︎

Linux Full Course for Beginners | Learn Linux System Administration

Learn Kubernetes in 6 Hours – Full Course with Real-World Project
▶︎

Learn Kubernetes in 6 Hours – Full Course with Real-World Project

System Design Explained: APIs, Databases, Caching, CDNs, Load Balancing & Production Infra
▶︎

System Design Explained: APIs, Databases, Caching, CDNs, Load Balancing & Production Infra