Effective RBAC - Jordan Liggitt, Red Hat

  Рет қаралды 31,929

CNCF [Cloud Native Computing Foundation]

CNCF [Cloud Native Computing Foundation]

Күн бұрын

Effective RBAC - Jordan Liggitt, Red Hat
The v1 release of role-based access control (RBAC) in Kubernetes 1.8 provides a flexible way to ensure users and applications have proper access to the Kubernetes API. This talk is for administrators who want to secure their clusters, and for anyone who wants their applications to integrate easily in RBAC-enabled environments. This talk will give an overview of the RBAC design and API, explain how to set up an RBAC-enabled cluster, demonstrate applying policies to existing applications, show how to create custom roles to distribute with applications, and answer the question "Can Bob educate dolphins?"
About Jordan Liggitt
Jordan Liggitt is a principal software engineer at Red Hat, and helps lead Kubernetes authentication and authorization efforts.
Join us for KubeCon + CloudNativeCon in Barcelona May 20 - 23, Shanghai June 24 - 26, and San Diego November 18 - 21! Learn more at kubecon.io. The conference features presentations from developers and end users of Kubernetes, Prometheus, Envoy and all of the other CNCF-hosted projects.

Пікірлер: 19
@Yggdrasil42
@Yggdrasil42 6 жыл бұрын
This is one of the clearest RBAC explanations I've seen. Thanks.
@jo67534
@jo67534 6 жыл бұрын
Great talk!!! Clear and fun to watch. audit2rbac is so awesome. :) Thank you!!!!
@cokegen
@cokegen 4 жыл бұрын
Dude ... rebuilt my local kube cluster just to test this and it freaking works ... awesome both the talk and audit2rbac ... THANKS !
@fergusmacdermot5963
@fergusmacdermot5963 6 жыл бұрын
Great talk. Very clear, thanks.
@username-t1x
@username-t1x 5 жыл бұрын
Very clear explanation. Thank you sir!
@alenka11081
@alenka11081 6 жыл бұрын
Great presentation!
@gatsbylee2773
@gatsbylee2773 4 жыл бұрын
Wonderful!!
@navid4302
@navid4302 3 жыл бұрын
good representation, however, please remove distorting effect from the representation box. a rectangle is better than a trapezium :)
@vuthu1261
@vuthu1261 3 жыл бұрын
Superb.
@umamaheswariprabhakar9887
@umamaheswariprabhakar9887 6 жыл бұрын
Nice presentation, can you please post the slides?
@CostisPan
@CostisPan 5 жыл бұрын
Great talk
@jonassteinberg3779
@jonassteinberg3779 3 жыл бұрын
Great talk and a very watchable, if not disarming speaker; I'm not sure however I would have allowed the title of the talk to be "Effective" RBAC, as it's not exactly about "effective" rbac in the sense of rbac, it's about "effective" in the sense of automation, which is definitely not what I thought this talk was going to be about. The first half is simply a nice, gentle breakdown of k8s rbac scopes, effectively; and then the second half is him demoing a tool that builds roles for you. And while it's nice that the roles are naturally hardened as they are all automatically scoped via API call scope (which is great), the talk has *nothing* to do with organizing RBAC to meet various user needs and offers no generalized models for admins trying to role out, well...effective RBAC.
@daniel.deflax
@daniel.deflax 6 жыл бұрын
Thanks
@guangxuli5901
@guangxuli5901 6 жыл бұрын
awesome
@mikecoleman4628
@mikecoleman4628 6 жыл бұрын
50 DKP minus for pre recorded demo
@arunpln
@arunpln 4 жыл бұрын
Down voters are experts
@SebastianAcostaCheca
@SebastianAcostaCheca 5 жыл бұрын
isbit.mx
@xiamaosheng175
@xiamaosheng175 2 жыл бұрын
slides: github.com/sbueringer/kubecon-slides/blob/master/slides/2017-kubecon-na/Effective%20RBAC%20-%20Jordan%20Liggitt%2C%20Red%20Hat%20-%20Effective%20RBAC.pdf
CrashLoopBackoff, Pending, FailedMount and Friends: Debugging Common Kubernetes Cluster
34:54
CNCF [Cloud Native Computing Foundation]
Рет қаралды 23 М.
Securing Cluster Networking with Network Policies - Ahmet Balkan, Google
30:55
CNCF [Cloud Native Computing Foundation]
Рет қаралды 29 М.
Зачем он туда залез?
00:25
Vlad Samokatchik
Рет қаралды 2,3 МЛН
Was ist im Eis versteckt? 🧊 Coole Winter-Gadgets von Amazon
00:37
SMOL German
Рет қаралды 39 МЛН
Became invisible for one day!  #funny #wednesday #memes
00:25
Watch Me
Рет қаралды 59 МЛН
Despicable Me Fart Blaster
00:51
_vector_
Рет қаралды 21 МЛН
The dangers of role-based access control (RBAC)
30:13
Infosec
Рет қаралды 7 М.
Certifik8s: All You Need to Know About Certificates in Kubernetes [I] - Alexander Brand, Apprenda
35:57
CNCF [Cloud Native Computing Foundation]
Рет қаралды 44 М.
Kubernetes Security Best Practices - Ian Lewis, Google
28:53
CNCF [Cloud Native Computing Foundation]
Рет қаралды 49 М.
How Netflix Is Solving Authorization Across Their Cloud [I] - Manish Mehta & Torin Sandall, Netflix
36:25
CNCF [Cloud Native Computing Foundation]
Рет қаралды 86 М.
Kubernetes Storage Lingo 101 - Saad Ali, Google (Beginner Skill Level)
34:36
CNCF [Cloud Native Computing Foundation]
Рет қаралды 19 М.
Helm Chart Patterns [I] - Vic Iglesias, Google
28:32
CNCF [Cloud Native Computing Foundation]
Рет қаралды 37 М.
Hacking and Hardening Kubernetes Clusters by Example [I] - Brad Geesaman, Symantec
39:31
CNCF [Cloud Native Computing Foundation]
Рет қаралды 41 М.
Role Based Access Control (RBAC) with Kubernetes
10:24
School of Devops
Рет қаралды 67 М.
Kubernetes Design Principles: Understand the Why - Saad Ali, Google
37:53
CNCF [Cloud Native Computing Foundation]
Рет қаралды 125 М.
Зачем он туда залез?
00:25
Vlad Samokatchik
Рет қаралды 2,3 МЛН