Kubernetes Security - Implement pod to pod encryption by use of mTLS with Service Mesh - 16

  Рет қаралды 6,419

Learn with GVR

Learn with GVR

Күн бұрын

Kubernetes Security - Implement pod to pod encryption by use of mTLS with Service Mesh - 16
Chapters
00:00 About topic
00:22 Wha is TLS
04:14 TLS Architecture & How TLS works
07:59 mTLS
10:00 mTLS in Microservices
11:45 Service Mesh
13:05 What is Sidecar Container
14:39 ISTIO Architecture
16:00 IStIO Security Architecture
18:12 Linkerd Architecture
19:36 mTLS Communication flow in Service Mesh
22:41 mTLS between multiple kubernetes clusters
23:16 mTLS demo using Linkerd
CKS Preparation Guide Github: github.com/ramanagali/Intervi...
Managing TLS Documentation: kubernetes.io/docs/tasks/tls/...
Istio Service Mesh: istio.io/latest/docs/setup/ge...
LinkerdService Mesh: linkerd.io/2.11/overview/
Istio Service Mesh Video: • Istio Service Mesh for...
Istio Service Mesh Demo Video: • Kubernetes Istio Servi...
CKS playlist: • Certified Kubernetes S...
Like, Comment & Subscribe Learn with GVR
#cks #kubenetes #kubernetessecurity #k8s #learnwithgvr

Пікірлер: 17
@seanwalker2555
@seanwalker2555 4 ай бұрын
great video.
@learnwithgvr
@learnwithgvr 4 ай бұрын
Thank you, keep learning
@saikishore158
@saikishore158 Жыл бұрын
Good Presentation
@learnwithgvr
@learnwithgvr Жыл бұрын
Thank you, keep learning
@brahmadarapaneni4561
@brahmadarapaneni4561 Жыл бұрын
Usually server does not ask client cert how server knows I need to ask for client cert,
@learnwithgvr
@learnwithgvr Жыл бұрын
I have made video on TLS communications, pls watch kzbin.info/www/bejne/hXnQmJVtnZJlY8k thank you
@humayunsabid3188
@humayunsabid3188 9 ай бұрын
Hello Sir, which type of question can be asked in the cks exam from this section, Thanks in advance.
@learnwithgvr
@learnwithgvr 9 ай бұрын
There is video uploaded on this kzbin.info/www/bejne/nqnSqWxrap2ioKc
@deepdeep4629
@deepdeep4629 Жыл бұрын
do we have to use linkerd for cks ?
@learnwithgvr
@learnwithgvr Жыл бұрын
LinkerD is one good example, you can also leverage custom solution or any other service mesh
@brahmadarapaneni4561
@brahmadarapaneni4561 Жыл бұрын
Does any difference in generating clients vs server certs
@learnwithgvr
@learnwithgvr Жыл бұрын
Server certificates are intended for securing communication between a server and a client. They typically include the server's hostname or IP address in the Subject Alternative Name (SAN) extension, which allows clients to verify that they are communicating with the intended server. Server certificates may also include additional extensions like Extended Key Usage (EKU) and Authority Key Identifier (AKI) to provide additional security and verification. Client certificates, on the other hand, are intended for verifying the identity of a client to a server. They typically include the client's distinguished name (DN) in the Subject field and may also include a unique identifier in the SAN extension. Client certificates may also include EKU and AKI extensions to provide additional security and verification. When generating client and server certificates, the certificate authority (CA) may also use different certificate templates or configurations based on their intended usage. For example, a CA may issue server certificates with longer key lengths and shorter expiration periods than client certificates, to provide greater security for the server-side communications.
@brahmadarapaneni4561
@brahmadarapaneni4561 Жыл бұрын
@@learnwithgvr super sir, may I know client certs distinguished name(DN) , how it's verify this name and confirms this client is good
@corwaincyrus5
@corwaincyrus5 2 жыл бұрын
Following...
@learnwithgvr
@learnwithgvr 2 жыл бұрын
Thanks
@deepdeep4629
@deepdeep4629 Жыл бұрын
you have also consul connect
@learnwithgvr
@learnwithgvr Жыл бұрын
Sorry, dont have on Consul
Kubernetes Security - Minimize base image footprint - 17
37:33
Learn with GVR
Рет қаралды 1,3 М.
What Is Mutual TLS (mTLS), Why Do We Need It, And How Do We Get It?
19:05
Cat Corn?! 🙀 #cat #cute #catlover
00:54
Stocat
Рет қаралды 16 МЛН
НРАВИТСЯ ЭТОТ ФОРМАТ??
00:37
МЯТНАЯ ФАНТА
Рет қаралды 1,6 МЛН
Now THIS is entertainment! 🤣
00:59
America's Got Talent
Рет қаралды 38 МЛН
تجربة أغرب توصيلة شحن ضد القطع تماما
00:56
صدام العزي
Рет қаралды 58 МЛН
Rotating certificates in Istio
41:41
solo.io
Рет қаралды 1 М.
Service Mesh 101: an introduction with Linkerd
13:19
Buoyant
Рет қаралды 13 М.
Kubernetes Security - Open Policy Agent - OPA Gatekeeper - 12
36:31
Learn with GVR
Рет қаралды 7 М.
Cert Manager for securing pod to pod communication
14:39
Houssem Dellai
Рет қаралды 5 М.
Cat Corn?! 🙀 #cat #cute #catlover
00:54
Stocat
Рет қаралды 16 МЛН