Seccomp Security Profiles and You: A Practical Guide - Duffie Cooley, VMware

  Рет қаралды 4,063

CNCF [Cloud Native Computing Foundation]

CNCF [Cloud Native Computing Foundation]

Күн бұрын

Don’t miss out! Join us at our upcoming events: EnvoyCon Virtual on October 15 and KubeCon + CloudNativeCon North America 2020 Virtual from November 17-20. Learn more at kubecon.io. The conferences feature presentations from developers and end users of Kubernetes, Prometheus, Envoy, and all of the other CNCF-hosted projects.
Seccomp Security Profiles and You: A Practical Guide - Duffie Cooley, VMware
Have you wondered what a seccomp security profile is, and how it relates to Linux Capabilities? Folks often dismiss seccomp profiles and Capabilities as a way of hardening applications as it is too difficult to determine what syscalls are in use by a given application. In this session we will explore a couple of tools designed to make this more approachable. Dockersl.im is an opensource project that can take a Dockerfile and an image and produce a smaller image containing only the necessary bits, a seccomp security profile derived from the system calls the application made while under test. Inspektor Gadget is an opensource project by the folks at kinvolk that enables to make use of BPF to inspect a number of things about pods that are deployed. Providing better visibility into what pods are accessing from a syscall and filesystem perspective. Come learn about these super powers!
sched.co/ZetL

Пікірлер: 6
@ranjitpradhan7915
@ranjitpradhan7915 Жыл бұрын
This is a really detailed overview of Linux CAPs and SYS calls, thank you!
@user-hs6gp8gb9l
@user-hs6gp8gb9l 9 ай бұрын
Great presentation Duffie. It seems we share the same surname in addition to professional interests
@hrvojetonkovac6519
@hrvojetonkovac6519 3 жыл бұрын
Great talk
@bohrasdf
@bohrasdf 2 жыл бұрын
This is soooo good
@jmfda00
@jmfda00 2 жыл бұрын
such a nice talk!
@barma1309
@barma1309 3 жыл бұрын
Thank you!!!
eBPF and Kubernetes: Little Helper Minions for Scaling Microservices - Daniel Borkmann, Cilium
39:29
CNCF [Cloud Native Computing Foundation]
Рет қаралды 11 М.
Seccomp: What Can It Do For You? - Justin Cormack, Docker
34:27
CNCF [Cloud Native Computing Foundation]
Рет қаралды 2,5 М.
Can This Bubble Save My Life? 😱
00:55
Topper Guild
Рет қаралды 70 МЛН
Comfortable 🤣 #comedy #funny
00:34
Micky Makeover
Рет қаралды 17 МЛН
Logo Matching Challenge with Alfredo Larin Family! 👍
00:36
BigSchool
Рет қаралды 21 МЛН
Intro to Rook: Storage for Kubernetes - Jared Watts, Upbound & Alexander Trost, Cloudical
31:16
CNCF [Cloud Native Computing Foundation]
Рет қаралды 6 М.
Introduction to containerd - Phil Estes, IBM & Derek McGowan, Docker
24:19
CNCF [Cloud Native Computing Foundation]
Рет қаралды 14 М.
Istio - The Packet's-Eye View - Matt Turner, Tetrate
36:07
CNCF [Cloud Native Computing Foundation]
Рет қаралды 12 М.
Running K3s, Lightweight Kubernetes, in Production for the Edge & Beyond - Darren Shepherd, Rancher
26:36
CNCF [Cloud Native Computing Foundation]
Рет қаралды 10 М.
The Tragedy of systemd
47:18
linux.conf.au
Рет қаралды 1,1 МЛН
Certifik8s: All You Need to Know About Certificates in Kubernetes [I] - Alexander Brand, Apprenda
35:57
CNCF [Cloud Native Computing Foundation]
Рет қаралды 44 М.
ПОЧЕМУ МИКРОФОНЫ ИГРОВЫЕ? 🧐
0:46
KEKTAR
Рет қаралды 718 М.
ноутбуки от 7.900 в тг laptopshoptop
0:14
Ноутбуковая лавка
Рет қаралды 4 МЛН
ГОТОВЫЙ ПК с OZON за 5000 рублей
20:24
Ремонтяш
Рет қаралды 325 М.
💀СЛОМАЛ Айфон за 5 СЕКУНД😱
0:26
Demin's Lounge
Рет қаралды 144 М.
Электронный звонок #shorts
0:26
TheBestBike
Рет қаралды 396 М.