Kubernetes Security 2 - Pod Security Policy for Kubernetes Cluster

  Рет қаралды 4,861

Shailender Choudhary

Shailender Choudhary

Күн бұрын

This video explains the Pod security policy in Kubernetes. PSP provides an extra layer of security over RBAC. Though PSP is deprecated from version 1.21 but still it carries a good weightage in CKS exam and previous cluster versions still have to use PSP for pod level security.
Most famous security control aspects are:
Running of privileged containers
Usage of host namespaces(HostPID)
Usage of volume types
Usage of the host filesystem
Requiring the use of a read only root file system
Restricting escalation to root privileges

Пікірлер: 8
@SandeepSaini-mt3yl
@SandeepSaini-mt3yl 17 күн бұрын
Great explanation and clearly all doubts
@rugabajeanpierre8660
@rugabajeanpierre8660 2 жыл бұрын
thanks for explaining the PSP with examples
@aprann9012
@aprann9012 2 жыл бұрын
very helpful..thanks
@rameshd3951
@rameshd3951 Жыл бұрын
Nice one .
@iammrchetan
@iammrchetan 11 ай бұрын
Hi @Shailender, I want to restrict users from running cp/scp/rsync/sftp commands inside the containers running in the kubernetes. I understand that we should only have needed packages available inside the application images. But in our system, lots of applications are already running and we can't control that as of now. I was wondering if we have a way to achieve the same by using PodSecurityPolicy or PodSecurity admission controller. Let me know your thoughts around the same.
@180doman
@180doman Жыл бұрын
I think you have error (or i dont get it). You used Policy Name instead of Role Name in your role binding command. You should probably use --clusterrole-permissive-role instead of --clusterrole=limited-allow.
@ashumaheshwari1
@ashumaheshwari1 Жыл бұрын
@sudhir : Thanks for the video can we get the yaml files used in demo, if possible put them in git hub and share the link
@amitpawar3859
@amitpawar3859 Жыл бұрын
nice video.. Very informative tutorial...
Kubernetes Security 1 - Network Policy for Kubernetes Cluster
15:11
Shailender Choudhary
Рет қаралды 2,1 М.
Kubernetes Security: Pod Security Context
9:08
kubetrain
Рет қаралды 7 М.
КАК ДУМАЕТЕ КТО ВЫЙГРАЕТ😂
00:29
МЯТНАЯ ФАНТА
Рет қаралды 8 МЛН
Red❤️+Green💚=
00:38
ISSEI / いっせい
Рет қаралды 76 МЛН
Kubernetes Pause Containers - Certified Kubernetes Administrator
10:58
networknutsdotnet
Рет қаралды 2,9 М.
Kubernetes Security Best Practices 2021 (From Container Specialist)
17:01
Automatic Ingress TLS with LetsEncrypt in Azure AKS
17:45
Shailender Choudhary
Рет қаралды 14 М.
Kubernetes Security - Pod Security Policies (PodSecurityPolicy) - 11
35:58
Autoscaling in Kubernetes
19:07
Pavan Elthepu
Рет қаралды 20 М.
Kubernetes Network Policy Tutorial - yaml explained + Demo Calico
15:35
Hacking a Kubernetes Cluster: A Practical Example!
11:51
KodeKloud
Рет қаралды 62 М.
Kubernetes Security Best Practices - Ian Lewis, Google
28:53
CNCF [Cloud Native Computing Foundation]
Рет қаралды 49 М.
Kubernetes Security - Security Context for a Pod or Container - 13
23:01
Как бесплатно замутить игровой ноутбук
1:00
ЖЕЛЕЗНЫЙ КОРОЛЬ
Рет қаралды 238 М.
Cheapest gaming phone? 🤭 #miniphone #smartphone #iphone #fy
0:19
Pockify™
Рет қаралды 4,1 МЛН
АЙФОН 20 С ФУНКЦИЕЙ ВИДЕНИЯ ОГНЯ
0:59
КиноХост
Рет қаралды 1,1 МЛН
СТРАШНЫЙ ВИРУС НА МАКБУК
0:39
Кринжовый чел
Рет қаралды 1,4 МЛН
EXEED VX 2024: Не өзгерді?
9:06
Oljas Oqas
Рет қаралды 46 М.
Смартфон УЛУЧШАЕТ ЗРЕНИЕ!?
0:41
ÉЖИ АКСЁНОВ
Рет қаралды 1,1 МЛН