Container security: Do containers actually contain? Should you care? - 2015 Red Hat Summit

  Рет қаралды 9,456

Red Hat Summit

Red Hat Summit

Күн бұрын

Daniel Walsh - Mr SELinux, Red Hat
As container use gains popularity, container security is more important than ever. This talk is split into 4 parts detailing security measures in containers, signing, authentication and authorization with the daemon, and mandatory access control.
In this session, you will:
-Learn about the security measures in container management that control what processes within a container can do, and hear about upcoming security enhancements to containers.
-See how container images are signed.
-Discover authentication updates being made to the server to control who’s able to manipulate a container, and learn how developers are splitting functions that an authenticated user is allowed to do on the server.
-Learn how SELinux works and how it works with Docker.

Пікірлер: 14
@geraldjustice1009
@geraldjustice1009 8 жыл бұрын
Sadly the camera focussed too often on the speaker and some slides were not shown or were shown far too quickly.
@unixbhaskar
@unixbhaskar 9 жыл бұрын
Cool Dan! love your work and talk...way to go...cheers mate.
@dejagerlaubscher5127
@dejagerlaubscher5127 8 жыл бұрын
this is awesome training !
@zofe
@zofe 3 жыл бұрын
Backward-compatibility is backward socioeconomic mentality of tuning and patching, rather not R&D thus replacing engineers with copycats - who exponentiate compexity. Jim Keller, a prominent CPU design-leader, states that a 5-years cycle of redesign from scratch makes sense for CPUs ... so what about OS fundamentals, then? kzbin.info/www/bejne/hJOVpZiYjqaUhaM
@VasuThiyagarajan
@VasuThiyagarajan 8 жыл бұрын
Containers don't contain...but if you get it from RHEL it does...seriously ?
@TerryBowling
@TerryBowling 8 жыл бұрын
+Vasu Thiyagarajan That is not what he is saying at all. I think you need to listen more carefully. He is saying that it is naive to think that containers truly contain all by themselves. SELinux improves security significantly and Red Hat is working with the community to add things like SECCOMP and User Name Spaces to improve this further. So if you're blindly using containers thinking it's secure, you're wrong. If you're using the Red Hat ecosystem, Red Hat is helping you to fill the gaps. Not saying you can't do it with other platforms, but there is a lot to know and Red Hat has the most engineers and security resources to ensure the gaps are identified and filled. And we submit for the government security certifications (CC, FIPS, etc) so there are additional audits and eyeballs critiquing the platform.
@VasuThiyagarajan
@VasuThiyagarajan 8 жыл бұрын
Thanks for clarification
@johnschiwitz4412
@johnschiwitz4412 8 жыл бұрын
I enjoyed your systemd talk last June. I noticed you went to Holy Cross and WPI I worked at Holy Cross and lived on Salisbury Street about a mile from WPI. We are implementing containers here at Honda, thanks again for clearing up these topics
9 жыл бұрын
Do *you* have pigs in a park?
@tomascrhonek
@tomascrhonek 9 жыл бұрын
Video jsem neviděl, ale když jsem četl u nspawnu, že securita ještě není moc doladěná, tak jsem si myslel, že je to takové to klasické co se týká všech kontejnerů. No a v stačilo si dát v nspawnu cat /proc/mounts a bylo celkem jasné, jak moc je ta bezpečnost nedoladěná. Tím nehodnotím, jestli je to dobře nebo špatně, ale člověk by měl znát co všechno to propustí dovnitř kontejneru.
9 жыл бұрын
Nspawn byl vytvořen pro testovani systemd. Do budoucna by se ale mohl pouzivat do produkce. Ambice takove nemel, ale vypada to, ze se uchyti.
@tomascrhonek
@tomascrhonek 9 жыл бұрын
To je možné, já jej používám na testování aplikací, které vyžadují nějaké jiné nastavení systému než má aktuálně hostitel. Po testování následuje btrfs sub del. Na bezpečnostní oddělení bych asi žádný kontejner nepoužil.
@rhc287
@rhc287 6 жыл бұрын
Great talk.
@kadiatoutraore9538
@kadiatoutraore9538 8 жыл бұрын
awa fjg
Security-enhanced Linux for mere mortals - 2015 Red Hat Summit
52:18
Red Hat Summit
Рет қаралды 65 М.
Are you listening to what SELinux is telling you?
1:03:14
Red Hat Summit
Рет қаралды 14 М.
Миллионер | 1 - серия
34:31
Million Show
Рет қаралды 1,8 МЛН
Inside Out 2: BABY JOY VS SHIN SONIC 3
00:19
AnythingAlexia
Рет қаралды 9 МЛН
Burr Sutter & company blow your mind at Red Hat Summit 2016
41:12
Red Hat Summit
Рет қаралды 13 М.
Run containers on bare metal already!
41:12
Bryan Cantrill
Рет қаралды 37 М.
Demystifying systemd
44:59
Red Hat Summit
Рет қаралды 24 М.
Container Security Best Practices
27:15
HashiCorp
Рет қаралды 8 М.
2012 Red Hat Summit: SELinux For Mere Mortals
52:10
Red Hat
Рет қаралды 102 М.
BlackRock: The Conspiracies You Don’t Know
15:13
More Perfect Union
Рет қаралды 2 МЛН
What is a Container?
18:24
VMware Cloud Native Apps
Рет қаралды 666 М.
Миллионер | 1 - серия
34:31
Million Show
Рет қаралды 1,8 МЛН